Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.rebrand.ly/business-page-994/

Overview

General Information

Sample URL:http://www.rebrand.ly/business-page-994/
Analysis ID:1589276
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
HTML page contains hidden javascript code
Yara detected suspended webpage

Classification

  • System is w10x64
  • chrome.exe (PID: 1360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3244 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2020,i,4007739357911232359,13819848889530185223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6604 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rebrand.ly/business-page-994/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dropped/chromecache_42JoeSecurity_suspendedwebpageYara detected suspended webpageJoe Security
    SourceRuleDescriptionAuthorStrings
    0.0.pages.csvJoeSecurity_suspendedwebpageYara detected suspended webpageJoe Security
      No Sigma rule has matched
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: http://www.rebrand.ly/business-page-994/Avira URL Cloud: detection malicious, Label: phishing
      Source: http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="72" height="72" viewBox="0 0 72 72"> <path fill="#FFF" fill-rule="nonzero" d="M39.527 8.094l27.824 52.02A4 4 0 0 1 63.824 66H8.176a4 4 0 0 1-3.527-5.887L32.473 8.094a4 4 0 0 1 7.054 0zM36 57a3 3 0 1 0 0-6...
      Source: Yara matchFile source: 0.0.pages.csv, type: HTML
      Source: Yara matchFile source: dropped/chromecache_42, type: DROPPED
      Source: http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939HTTP Parser: No favicon
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /not-found HTTP/1.1Host: www.rebrandly.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.rebrand.ly/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /not-found HTTP/1.1Host: www.rebrandly.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /business-page-994/ HTTP/1.1Host: www.rebrand.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939 HTTP/1.1Host: www.rebrand.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.rebrand.lyConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: www.rebrand.ly
      Source: global trafficDNS traffic detected: DNS query: www.rebrandly.com
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Sat, 11 Jan 2025 23:22:19 GMTContent-Type: text/htmlContent-Length: 2623Connection: keep-aliveServer: AmazonS3Accept-Ranges: bytesAge: 55976ETag: "403355a474fb4486cfd7297b6fe374f3"Last-Modified: Thu, 17 Feb 2022 13:49:52 GMTVia: 1.1 6784ac36b8d920a78daf15294a50025e.cloudfront.net (CloudFront)Engine: Rebrandly.redirect, version 2.1x-amz-server-side-encryption: AES256x-amz-version-id: 0Ou37jKCUePL5aO7kLp5FP9Ly.sMxBw9X-Cache: Error from cloudfrontX-Amz-Cf-Pop: IAD79-C3X-Amz-Cf-Id: V2OGC0DRF2aX78yPHu3Lff_sWfLUyY5Ce7qtxe8JfjKEWLfn_j2grQ==Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 20 3c 73 74 79 6c 65 3e 68 74 6d 6c 2c 20 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 20 30 3b 20 2d 77 65 62 6b 69 74 2d 66 6f 6e 74 2d 73 6d 6f 6f 74 68 69 6e 67 3a 20 61 6e 74 69 61 6c 69 61 73 65 64 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 53 61 6e 73 2d 53 65 72 69 66 3b 7d 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 62 37 33 62 33 63 3b 20 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 33 33 3b 20 6c 65 74 74 65 72 2d 73 70 61 63 69 6e 67 3a 20 2d 30 2e 31 70 78 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 33 30 30 3b 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 73 74 79 6c 65 3a 20 6e 6f 72 6d 61 6c 3b 20 66 6f 6e 74 2d 73 74 72 65 74 63 68 3a 20 6e 6f 72 6d 61 6c 3b 7d 2e 69 63 6f 6e 2d 77 61 72 6e 69 6e 67 7b 77 69 64 74 68 3a 20 37 32 70 78 3b 7d 2e 74 69 74 6c 65 7b 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 34 38 70 78 3b 7d 64 69 76 7b 6d 61 78 2d 77 69 64 74 68 3a 20 38 30 30 70 78 3b 7d 61 2c 20 61 3a 68 6f 76 65 72 2c 20 61 3a 76 69 73 69 74 65 64 7b 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 20 75 6e 64 65 72 6c 69 6e 65 3b 7d 2e 6d 65 73 73 61 67 65 7b 66 6f 6e 74 2d 73 69 7a 65 3a 20 32 30 70 78 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 34 3b 20 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 31 36 70 78 3b 20 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 20 34 38 70 78 3b 7d 2e 6d 65 73 73 61 67 65 20 73 74 72 6f 6e 67 7b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 36 30 30 3b 20 6c 65 74 74 65 72 2d 73 70 61 Data Ascii: <html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: classification engineClassification label: mal48.win@16/2@8/6
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2020,i,4007739357911232359,13819848889530185223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rebrand.ly/business-page-994/"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2020,i,4007739357911232359,13819848889530185223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      1
      Process Injection
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Ingress Tool Transfer
      Traffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      http://www.rebrand.ly/business-page-994/100%Avira URL Cloudphishing
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://www.rebrand.ly/favicon.ico0%Avira URL Cloudsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      www.rebrand.ly
      15.197.137.111
      truefalse
        unknown
        www.google.com
        142.250.186.164
        truefalse
          high
          www.rebrandly.com
          18.66.102.21
          truefalse
            high
            NameMaliciousAntivirus DetectionReputation
            http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939true
              unknown
              https://www.rebrandly.com/not-foundfalse
                high
                http://www.rebrand.ly/business-page-994/true
                  unknown
                  http://www.rebrand.ly/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  15.197.137.111
                  www.rebrand.lyUnited States
                  7430TANDEMUSfalse
                  18.66.102.21
                  www.rebrandly.comUnited States
                  3MIT-GATEWAYSUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.186.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  192.168.2.6
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1589276
                  Start date and time:2025-01-12 00:21:19 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 4s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://www.rebrand.ly/business-page-994/
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.win@16/2@8/6
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.250.185.78, 74.125.133.84, 142.250.185.206, 142.250.186.46, 172.217.23.110, 199.232.210.172, 192.229.221.95, 142.250.184.206, 142.250.186.174, 142.250.181.238, 216.58.206.67, 2.23.242.162, 52.149.20.212, 13.107.246.45
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                  • Not all processes where analyzed, report is missing behavior information
                  • VT rate limit hit for: http://www.rebrand.ly/business-page-994/
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with very long lines (2623), with no line terminators
                  Category:downloaded
                  Size (bytes):2623
                  Entropy (8bit):5.426888206506014
                  Encrypted:false
                  SSDEEP:48:oJ9wxqwzph0KVO9vnbnSOrLOwOzsdCZf/rHX7SafCUeOvjtDYd:oJ9Eqaph0WO9vnbnSOPOwOzu6/raU75G
                  MD5:403355A474FB4486CFD7297B6FE374F3
                  SHA1:B03228CDDA53F19F4EC05F2A391C42D7EEBB4688
                  SHA-256:74D48DF2CA3D871809AB8FFE35DC49CCDB979E54A8B1C01841910E30D41EED68
                  SHA-512:9318738AC55CAD59F5110FF0C296A2BBCF314B397DDCC56290EA873A2B81D53E5CD05C6BCE84343C29D0BEF550AAF7AB48E84F207BECEBBD6F5928A3870252D7
                  Malicious:false
                  Reputation:low
                  URL:http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939
                  Preview:<html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff; text-decoration: underline;}.message{font-size: 20px; line-height: 1.4; margin-top: 16px; margin-bottom: 48px;}.message strong{font-weight: 600; letter-spacing: normal;}.note{font-size: 15px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 16px;}.cta_rebrandly{margin-top: 125px;}p.cta_rebrandly span{border-radius: 4px; border: solid 1px #ffffff; padding: 8px 24px; text-decoration: none; -moz-transition: all .2s ease-in; -o-transition: all .2s ease-in; -webkit-transition: all .2s ease-in
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 12, 2025 00:22:15.165750027 CET49675443192.168.2.4173.222.162.32
                  Jan 12, 2025 00:22:16.614177942 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:16.614207983 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:16.614264965 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:16.614495039 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:16.614510059 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.256464005 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.256903887 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:17.256926060 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.258519888 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.258600950 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:17.259793997 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:17.259891987 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.306020021 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:17.306039095 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:17.352888107 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:18.814069986 CET4973980192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:18.814186096 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:18.818927050 CET804973915.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:18.818991899 CET4973980192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:18.819051981 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:18.819111109 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:18.819566011 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:18.824434996 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.466962099 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.471221924 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:19.477356911 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.589884043 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.589940071 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.589973927 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.590123892 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:19.634867907 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:19.673067093 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:19.679290056 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.785254002 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:22:19.811777115 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:19.811813116 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:19.811867952 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:19.812119007 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:19.812133074 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:19.836549044 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:22:20.594675064 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.649724007 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:20.721466064 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:20.721477985 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.722615004 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.722629070 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.722681046 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:20.748621941 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:20.748709917 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.749372005 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:20.749387026 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:20.790359974 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.353065014 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:21.354887009 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.354957104 CET4434974218.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:21.355014086 CET49742443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.389899969 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.389934063 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:21.390027046 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.390393019 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:21.390404940 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.114465952 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.115075111 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.115101099 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.116082907 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.116163969 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.116434097 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.116497040 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.116563082 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.159332991 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.165353060 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.165364981 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.212239981 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.813157082 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823179007 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823189974 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823225975 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823287010 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823290110 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823293924 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.823497057 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823506117 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.823508024 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.823558092 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.904541016 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.904555082 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.904611111 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.904655933 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.904670000 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.904716015 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.919440031 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.919465065 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.919552088 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.919567108 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.919608116 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.980293989 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.980386019 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.990449905 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:22.990525961 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:22.990539074 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:23.000869036 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:23.000921965 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:23.000945091 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:23.000952005 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:23.000971079 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:23.000998974 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:23.001032114 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:23.002541065 CET49743443192.168.2.418.66.102.21
                  Jan 12, 2025 00:22:23.002557039 CET4434974318.66.102.21192.168.2.4
                  Jan 12, 2025 00:22:27.174175978 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:27.174359083 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:22:27.174422026 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:28.043026924 CET49737443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:22:28.043042898 CET44349737142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:03.821846008 CET4973980192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:03.826785088 CET804973915.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:04.790673971 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:04.797241926 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:16.558135986 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:16.558177948 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:16.558286905 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:16.558610916 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:16.558650017 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:17.242141008 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:17.242522001 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:17.242584944 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:17.243062019 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:17.243576050 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:17.243671894 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:17.290865898 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:19.180351973 CET804973915.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:19.180542946 CET4973980192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:19.788198948 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:19.788427114 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:20.042686939 CET4973980192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:20.042726994 CET4974080192.168.2.415.197.137.111
                  Jan 12, 2025 00:23:20.047533989 CET804973915.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:20.047559023 CET804974015.197.137.111192.168.2.4
                  Jan 12, 2025 00:23:27.142143011 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:27.142209053 CET44349799142.250.186.164192.168.2.4
                  Jan 12, 2025 00:23:27.142347097 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:28.042757988 CET49799443192.168.2.4142.250.186.164
                  Jan 12, 2025 00:23:28.042824984 CET44349799142.250.186.164192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 12, 2025 00:22:13.114953041 CET53624941.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:13.307713032 CET53530951.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:14.317675114 CET53543231.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:16.494815111 CET5769253192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:16.494947910 CET4993953192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:16.613276005 CET53576921.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:16.613327026 CET53499391.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:18.802988052 CET6069253192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:18.803421974 CET5617753192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:18.811799049 CET53561771.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:18.813463926 CET53606921.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:19.790934086 CET6453253192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:19.791057110 CET5947253192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:19.811136007 CET53645321.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:19.811167955 CET53594721.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:21.359956026 CET6350753192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:21.360177040 CET5428953192.168.2.41.1.1.1
                  Jan 12, 2025 00:22:21.379154921 CET53542891.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:21.389524937 CET53635071.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:31.408432961 CET53603231.1.1.1192.168.2.4
                  Jan 12, 2025 00:22:31.984030962 CET138138192.168.2.4192.168.2.255
                  Jan 12, 2025 00:22:50.282752991 CET53545731.1.1.1192.168.2.4
                  Jan 12, 2025 00:23:12.584656954 CET53504001.1.1.1192.168.2.4
                  Jan 12, 2025 00:23:13.299706936 CET53633081.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Jan 12, 2025 00:22:16.494815111 CET192.168.2.41.1.1.10x4a5cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:16.494947910 CET192.168.2.41.1.1.10x739cStandard query (0)www.google.com65IN (0x0001)false
                  Jan 12, 2025 00:22:18.802988052 CET192.168.2.41.1.1.10xd1c8Standard query (0)www.rebrand.lyA (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:18.803421974 CET192.168.2.41.1.1.10x44f4Standard query (0)www.rebrand.ly65IN (0x0001)false
                  Jan 12, 2025 00:22:19.790934086 CET192.168.2.41.1.1.10x2bc7Standard query (0)www.rebrandly.comA (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:19.791057110 CET192.168.2.41.1.1.10x9638Standard query (0)www.rebrandly.com65IN (0x0001)false
                  Jan 12, 2025 00:22:21.359956026 CET192.168.2.41.1.1.10xf9ceStandard query (0)www.rebrandly.comA (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:21.360177040 CET192.168.2.41.1.1.10xadc4Standard query (0)www.rebrandly.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Jan 12, 2025 00:22:16.613276005 CET1.1.1.1192.168.2.40x4a5cNo error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:16.613327026 CET1.1.1.1192.168.2.40x739cNo error (0)www.google.com65IN (0x0001)false
                  Jan 12, 2025 00:22:18.813463926 CET1.1.1.1192.168.2.40xd1c8No error (0)www.rebrand.ly15.197.137.111A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:18.813463926 CET1.1.1.1192.168.2.40xd1c8No error (0)www.rebrand.ly3.33.143.57A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:19.811136007 CET1.1.1.1192.168.2.40x2bc7No error (0)www.rebrandly.com18.66.102.21A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:19.811136007 CET1.1.1.1192.168.2.40x2bc7No error (0)www.rebrandly.com18.66.102.102A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:19.811136007 CET1.1.1.1192.168.2.40x2bc7No error (0)www.rebrandly.com18.66.102.111A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:19.811136007 CET1.1.1.1192.168.2.40x2bc7No error (0)www.rebrandly.com18.66.102.127A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:21.389524937 CET1.1.1.1192.168.2.40xf9ceNo error (0)www.rebrandly.com18.66.102.21A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:21.389524937 CET1.1.1.1192.168.2.40xf9ceNo error (0)www.rebrandly.com18.66.102.102A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:21.389524937 CET1.1.1.1192.168.2.40xf9ceNo error (0)www.rebrandly.com18.66.102.111A (IP address)IN (0x0001)false
                  Jan 12, 2025 00:22:21.389524937 CET1.1.1.1192.168.2.40xf9ceNo error (0)www.rebrandly.com18.66.102.127A (IP address)IN (0x0001)false
                  • www.rebrand.ly
                    • www.rebrandly.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44974015.197.137.111803244C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Jan 12, 2025 00:22:18.819566011 CET447OUTGET /business-page-994/ HTTP/1.1
                  Host: www.rebrand.ly
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Jan 12, 2025 00:22:19.466962099 CET245INHTTP/1.1 302 Found
                  Date: Sat, 11 Jan 2025 23:22:19 GMT
                  Content-Length: 0
                  Connection: keep-alive
                  Location: http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939
                  Engine: Rebrandly.redirect, version 2.1
                  Jan 12, 2025 00:22:19.471221924 CET497OUTGET /business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939 HTTP/1.1
                  Host: www.rebrand.ly
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Jan 12, 2025 00:22:19.589884043 CET1236INHTTP/1.1 404 Not Found
                  Date: Sat, 11 Jan 2025 23:22:19 GMT
                  Content-Type: text/html
                  Content-Length: 2623
                  Connection: keep-alive
                  Server: AmazonS3
                  Accept-Ranges: bytes
                  Age: 55976
                  ETag: "403355a474fb4486cfd7297b6fe374f3"
                  Last-Modified: Thu, 17 Feb 2022 13:49:52 GMT
                  Via: 1.1 6784ac36b8d920a78daf15294a50025e.cloudfront.net (CloudFront)
                  Engine: Rebrandly.redirect, version 2.1
                  x-amz-server-side-encryption: AES256
                  x-amz-version-id: 0Ou37jKCUePL5aO7kLp5FP9Ly.sMxBw9
                  X-Cache: Error from cloudfront
                  X-Amz-Cf-Pop: IAD79-C3
                  X-Amz-Cf-Id: V2OGC0DRF2aX78yPHu3Lff_sWfLUyY5Ce7qtxe8JfjKEWLfn_j2grQ==
                  Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 20 3c 73 74 79 6c 65 3e 68 74 6d 6c 2c 20 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 20 30 3b 20 2d 77 65 62 6b 69 74 2d 66 6f 6e 74 2d 73 6d 6f 6f 74 68 69 6e 67 3a 20 61 6e 74 69 61 6c 69 61 73 65 64 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 53 61 6e 73 2d 53 65 72 69 66 3b 7d 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 62 37 33 62 33 63 3b 20 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 33 33 3b 20 6c 65 74 74 65 72 2d 73 70 61 63 69 6e 67 3a 20 2d 30 2e 31 70 78 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 33 30 30 3b 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 73 74 79 6c 65 3a 20 6e 6f [TRUNCATED]
                  Data Ascii: <html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff; text-decoration: underline;}.message{font-size: 20px; line-height: 1.4; margin-top: 16px; margin-bottom: 48px;}.message strong{font-weight: 600; letter-spa
                  Jan 12, 2025 00:22:19.589940071 CET1236INData Raw: 63 69 6e 67 3a 20 6e 6f 72 6d 61 6c 3b 7d 2e 6e 6f 74 65 7b 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 35 70 78 3b 20 77 68 69 74 65 2d 73 70 61 63 65 3a 20 6e 6f 77 72 61 70 3b 20 6f 76 65 72 66 6c 6f 77 3a 20 68 69 64 64 65 6e 3b 20 74 65 78 74 2d 6f
                  Data Ascii: cing: normal;}.note{font-size: 15px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 16px;}.cta_rebrandly{margin-top: 125px;}p.cta_rebrandly span{border-radius: 4px; border: solid 1px #ffffff; padding: 8px 24px;
                  Jan 12, 2025 00:22:19.589973927 CET754INData Raw: 41 77 65 6b 30 7a 4e 69 41 31 4e 32 45 7a 49 44 4d 67 4d 43 41 78 49 44 41 67 4d 43 30 32 49 44 4d 67 4d 79 41 77 49 44 41 67 4d 43 41 77 49 44 5a 36 62 54 41 74 4d 54 4a 68 4d 79 41 7a 49 44 41 67 4d 43 41 77 49 44 4d 74 4d 31 59 7a 4d 47 45 7a
                  Data Ascii: Awek0zNiA1N2EzIDMgMCAxIDAgMC02IDMgMyAwIDAgMCAwIDZ6bTAtMTJhMyAzIDAgMCAwIDMtM1YzMGEzIDMgMCAwIDAtNiAwdjEyYTMgMyAwIDAgMCAzIDN6Ii8+Cjwvc3ZnPgo="> <h1 class="title">Stop! Deceptive page ahead!</h1> <div class="message"> This short URL has been disab
                  Jan 12, 2025 00:22:19.673067093 CET440OUTGET /favicon.ico HTTP/1.1
                  Host: www.rebrand.ly
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Referer: http://www.rebrand.ly/business-page-994/?rb.routing.mode=proxy&rb.routing.signature=413939
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Jan 12, 2025 00:22:19.785254002 CET190INHTTP/1.1 302 Found
                  Date: Sat, 11 Jan 2025 23:22:19 GMT
                  Content-Length: 0
                  Connection: keep-alive
                  Location: https://www.rebrandly.com/not-found
                  Engine: Rebrandly.redirect, version 2.1
                  Jan 12, 2025 00:23:04.790673971 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44973915.197.137.111803244C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Jan 12, 2025 00:23:03.821846008 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44974218.66.102.214433244C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-01-11 23:22:20 UTC453OUTGET /not-found HTTP/1.1
                  Host: www.rebrandly.com
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: cross-site
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: http://www.rebrand.ly/
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-01-11 23:22:21 UTC830INHTTP/1.1 200 OK
                  Content-Type: text/html
                  Content-Length: 73703
                  Connection: close
                  Date: Sat, 11 Jan 2025 23:22:22 GMT
                  Last-Modified: Tue, 07 Jan 2025 14:32:43 GMT
                  x-amz-server-side-encryption: AES256
                  Cache-Control: no-cache, no-store, must-revalidate
                  Accept-Ranges: bytes
                  Server: AmazonS3
                  ETag: "aa87ff427d04890f5d59f20a6d2415ae"
                  Vary: Accept-Encoding
                  X-Cache: Miss from cloudfront
                  Via: 1.1 21c2c1b3872c539a34b64bcf45f4054c.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P2
                  Alt-Svc: h3=":443"; ma=86400
                  X-Amz-Cf-Id: Wt9X2AeAUij6yVKK-2LUFKYhGQ80wpdqwrH0L1LTa4q_wDsPowKhHg==
                  X-XSS-Protection: 1; mode=block
                  X-Frame-Options: DENY
                  Content-Security-Policy: frame-ancestors 'self'; upgrade-insecure-requests;
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44974318.66.102.214433244C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-01-11 23:22:22 UTC350OUTGET /not-found HTTP/1.1
                  Host: www.rebrandly.com
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: */*
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: cors
                  Sec-Fetch-Dest: empty
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2025-01-11 23:22:22 UTC830INHTTP/1.1 200 OK
                  Content-Type: text/html
                  Content-Length: 73703
                  Connection: close
                  Date: Sat, 11 Jan 2025 23:22:23 GMT
                  Last-Modified: Tue, 07 Jan 2025 14:32:43 GMT
                  x-amz-server-side-encryption: AES256
                  Cache-Control: no-cache, no-store, must-revalidate
                  Accept-Ranges: bytes
                  Server: AmazonS3
                  ETag: "aa87ff427d04890f5d59f20a6d2415ae"
                  Vary: Accept-Encoding
                  X-Cache: Miss from cloudfront
                  Via: 1.1 3aad72975c9da06e6d0903ad874f0b54.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P2
                  Alt-Svc: h3=":443"; ma=86400
                  X-Amz-Cf-Id: RWtaOBJrBuy7olPgzXKuUJrJA8jjOhWZNjMBifL4CVXvT1P-3adzgQ==
                  X-XSS-Protection: 1; mode=block
                  X-Frame-Options: DENY
                  Content-Security-Policy: frame-ancestors 'self'; upgrade-insecure-requests;
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  2025-01-11 23:22:22 UTC16384INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 68 74 74 70 2d 65 71 75 69 76 3d 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 20 68 74 74 70 2d 65 71 75 69 76 3d 78 2d 75 61 2d 63 6f 6d 70 61 74 69 62 6c 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 52 65 62 72 61 6e 64 6c 79 20 69 73 20 74 68 65 20 66 72 65 65 20 55 52 4c 20 53 68 6f 72 74 65 6e 65 72 20 50 6c 61 74 66 6f 72 6d 20 77 69 74 68 20 63 75 73 74 6f 6d 20 64 6f 6d 61 69 6e 73 20 74 6f 20 73 68 6f 72 74 65 6e 20 61 20 6c 6f 6e 67 20 6c 69 6e 6b 2e 20
                  Data Ascii: <!DOCTYPE html><html lang=en><head><meta content="text/html; charset=utf-8" http-equiv=Content-Type><meta content="ie=edge" http-equiv=x-ua-compatible><meta content="Rebrandly is the free URL Shortener Platform with custom domains to shorten a long link.
                  2025-01-11 23:22:22 UTC576INData Raw: 68 74 3a 31 2e 32 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 7d 7d 2e 5f 74 69 74 6c 65 5f 31 34 6a 33 76 5f 32 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 34 70 78 7d 2e 5f 6d 65 73 73 61 67 65 5f 31 34 6a 33 76 5f 36 7b 6d 61 72 67 69 6e 2d 74 6f 70 3a 32 34 70 78 7d 2e 5f 63 74 61 5f 31 34 6a 33 76 5f 31 30 7b 6d 61 72 67 69 6e 2d 74 6f 70 3a 33 32 70 78 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 61 75 74 6f 3b 6d 61 72 67 69 6e 2d 72 69 67 68 74 3a 61 75 74 6f 7d 2e 5f 71 72 5f 63 6f 64 65 5f 6d 6f 64 61 6c 5f 5f 69 6e 70 75 74 5f 63 6f 6e 74 61 69 6e 65 72 5f 31 70 77 77 77 5f 31 7b 77 69 64 74 68 3a 31 30 30 25 3b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 7d 2e 5f 71 72 5f 63 6f 64 65 5f 6d 6f 64 61 6c
                  Data Ascii: ht:1.2;text-align:center}}._title_14j3v_2{font-size:24px}._message_14j3v_6{margin-top:24px}._cta_14j3v_10{margin-top:32px;margin-left:auto;margin-right:auto}._qr_code_modal__input_container_1pwww_1{width:100%;display:flex;position:relative}._qr_code_modal
                  2025-01-11 23:22:22 UTC16384INData Raw: 6f 6e 74 65 6e 74 20 2e 46 6f 72 6d 5f 5f 63 6f 6e 74 72 6f 6c 7b 66 6c 65 78 2d 67 72 6f 77 3a 31 7d 2e 51 52 43 6f 64 65 41 63 74 69 6f 6e 5f 5f 73 69 7a 65 7b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 73 70 61 63 65 2d 62 65 74 77 65 65 6e 7d 2e 51 52 43 6f 64 65 41 63 74 69 6f 6e 5f 5f 73 69 7a 65 3e 2e 54 61 67 3a 68 6f 76 65 72 7b 74 72 61 6e 73 69 74 69 6f 6e 3a 2e 33 73 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 76 61 72 28 2d 2d 63 6f 6c 6f 72 2d 62 6c 75 65 2d 36 30 30 29 21 69 6d 70 6f 72 74 61 6e 74 7d 2e 5f 6e 6f 74 69 66 69 63 61 74 69 6f 6e 5f 6f 75 70 63 6b 5f 32 7b 6d 61 78 2d 77 69 64 74 68 3a 33 34 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 66 69 78 65 64 3b 74 6f 70 3a 39 30 70 78 3b 72 69 67 68 74 3a 63 61 6c 63 28 28 31
                  Data Ascii: ontent .Form__control{flex-grow:1}.QRCodeAction__size{justify-content:space-between}.QRCodeAction__size>.Tag:hover{transition:.3s;background-color:var(--color-blue-600)!important}._notification_oupck_2{max-width:340px;position:fixed;top:90px;right:calc((1
                  2025-01-11 23:22:22 UTC16384INData Raw: 71 75 6f 74 3b 61 77 73 2d 73 33 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 70 72 6f 76 69 64 65 72 5f 6d 65 74 61 64 61 74 61 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 2c 26 71 75 6f 74 3b 63 72 65 61 74 65 64 41 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 30 38 54 30 37 3a 33 39 3a 35 33 2e 30 31 38 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 75 70 64 61 74 65 64 41 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 30 38 54 30 37 3a 33 39 3a 35 33 2e 30 31 38 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 69 73 55 72 6c 53 69 67 6e 65 64 26 71 75 6f 74 3b 3a 5b 30 2c 74 72 75 65 5d 7d 5d 7d 5d 7d 5d 7d 5d 2c 5b 30 2c 7b 26 71 75 6f 74 3b 69 64 26 71 75 6f 74 3b 3a 5b 30 2c 38 37 5d 2c 26 71 75 6f
                  Data Ascii: quot;aws-s3&quot;],&quot;provider_metadata&quot;:[0,null],&quot;createdAt&quot;:[0,&quot;2024-08-08T07:39:53.018Z&quot;],&quot;updatedAt&quot;:[0,&quot;2024-08-08T07:39:53.018Z&quot;],&quot;isUrlSigned&quot;:[0,true]}]}]}]}],[0,{&quot;id&quot;:[0,87],&quo
                  2025-01-11 23:22:22 UTC2048INData Raw: 30 2c 26 71 75 6f 74 3b 53 53 4f 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 63 72 65 61 74 65 64 41 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 32 31 54 31 30 3a 33 31 3a 33 39 2e 33 33 37 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 75 70 64 61 74 65 64 41 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 32 38 54 30 39 3a 30 39 3a 31 33 2e 32 30 34 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 70 75 62 6c 69 73 68 65 64 41 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 32 31 54 31 30 3a 33 31 3a 34 31 2e 35 33 38 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 73 6c 75 67 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 65 6e 74 65 72 70 72 69 73 65 2d 73 65 63 75 72 69 74 79
                  Data Ascii: 0,&quot;SSO&quot;],&quot;createdAt&quot;:[0,&quot;2024-08-21T10:31:39.337Z&quot;],&quot;updatedAt&quot;:[0,&quot;2024-08-28T09:09:13.204Z&quot;],&quot;publishedAt&quot;:[0,&quot;2024-08-21T10:31:41.538Z&quot;],&quot;slug&quot;:[0,&quot;enterprise-security
                  2025-01-11 23:22:22 UTC8949INData Raw: 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 65 78 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 6d 69 6d 65 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 69 6d 61 67 65 2f 73 76 67 2b 78 6d 6c 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 73 69 7a 65 26 71 75 6f 74 3b 3a 5b 30 2c 30 2e 34 35 5d 2c 26 71 75 6f 74 3b 75 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 72 65 62 72 61 6e 64 6c 79 2e 63 6f 6d 2f 69 63 5f 72 6f 75 74 65 5f 37 34 36 61 34 33 32 63 32 31 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 70 72 65 76 69 65 77 55 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 2c 26 71 75 6f 74 3b 70 72 6f 76 69 64 65 72 26 71 75 6f 74 3b 3a 5b 30 2c
                  Data Ascii: quot;],&quot;ext&quot;:[0,&quot;.svg&quot;],&quot;mime&quot;:[0,&quot;image/svg+xml&quot;],&quot;size&quot;:[0,0.45],&quot;url&quot;:[0,&quot;https://cdn.rebrandly.com/ic_route_746a432c21.svg&quot;],&quot;previewUrl&quot;:[0,null],&quot;provider&quot;:[0,
                  2025-01-11 23:22:22 UTC12978INData Raw: 71 75 6f 74 3b 2f 6e 65 77 64 6f 6d 61 69 6e 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 69 63 6f 6e 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 69 63 2d 64 6f 6d 61 69 6e 2d 63 6f 6e 6e 65 63 74 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 74 69 74 6c 65 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 44 6f 6d 61 69 6e 20 6e 61 6d 65 20 72 65 67 69 73 74 72 61 74 69 6f 6e 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 74 61 72 67 65 74 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 2c 26 71 75 6f 74 3b 70 61 67 65 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71 75 6f 74 3b 64 61 74 61 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 7d 5d 2c 26 71 75 6f 74 3b 69 6d 61 67 65 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71 75 6f 74 3b 64 61 74 61 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71
                  Data Ascii: quot;/newdomain&quot;],&quot;icon&quot;:[0,&quot;ic-domain-connect&quot;],&quot;title&quot;:[0,&quot;Domain name registration&quot;],&quot;target&quot;:[0,null],&quot;page&quot;:[0,{&quot;data&quot;:[0,null]}],&quot;image&quot;:[0,{&quot;data&quot;:[0,{&q


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:18:22:10
                  Start date:11/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:18:22:10
                  Start date:11/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2020,i,4007739357911232359,13819848889530185223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:18:22:18
                  Start date:11/01/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rebrand.ly/business-page-994/"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly