Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://rebrand.ly/dfi21fe

Overview

General Information

Sample URL:http://rebrand.ly/dfi21fe
Analysis ID:1590428
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
Yara detected suspended webpage

Classification

  • System is w10x64
  • chrome.exe (PID: 3652 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=2020,i,13513465400319421349,3291854257070266711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://rebrand.ly/dfi21fe" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dropped/chromecache_42JoeSecurity_suspendedwebpageYara detected suspended webpageJoe Security
    SourceRuleDescriptionAuthorStrings
    0.0.pages.csvJoeSecurity_suspendedwebpageYara detected suspended webpageJoe Security
      No Sigma rule has matched
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: http://rebrand.ly/dfi21feAvira URL Cloud: detection malicious, Label: phishing
      Source: http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="72" height="72" viewBox="0 0 72 72"> <path fill="#FFF" fill-rule="nonzero" d="M39.527 8.094l27.824 52.02A4 4 0 0 1 63.824 66H8.176a4 4 0 0 1-3.527-5.887L32.473 8.094a4 4 0 0 1 7.054 0zM36 57a3 3 0 1 0 0-6...
      Source: Yara matchFile source: 0.0.pages.csv, type: HTML
      Source: Yara matchFile source: dropped/chromecache_42, type: DROPPED
      Source: http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151HTTP Parser: No favicon
      Source: global trafficTCP traffic: 192.168.2.4:57201 -> 1.1.1.1:53
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /not-found HTTP/1.1Host: www.rebrandly.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://rebrand.ly/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /not-found HTTP/1.1Host: www.rebrandly.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /dfi21fe HTTP/1.1Host: rebrand.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151 HTTP/1.1Host: rebrand.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: rebrand.lyConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: rebrand.ly
      Source: global trafficDNS traffic detected: DNS query: www.rebrandly.com
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 14 Jan 2025 00:37:02 GMTContent-Type: text/htmlContent-Length: 2623Connection: keep-aliveServer: AmazonS3Accept-Ranges: bytesAge: 42777ETag: "403355a474fb4486cfd7297b6fe374f3"Last-Modified: Thu, 17 Feb 2022 13:49:52 GMTVia: 1.1 3ebe5e903d733a5e00724b1dfdba02bc.cloudfront.net (CloudFront)Engine: Rebrandly.redirect, version 2.1x-amz-server-side-encryption: AES256x-amz-version-id: 0Ou37jKCUePL5aO7kLp5FP9Ly.sMxBw9X-Cache: Error from cloudfrontX-Amz-Cf-Pop: IAD79-C3X-Amz-Cf-Id: LZbMhgvK6vuz4XKrMLqhY4RlI9O5MgAc6MJcK8O93sFXgonFyXOGhg==Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 20 3c 73 74 79 6c 65 3e 68 74 6d 6c 2c 20 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 20 30 3b 20 2d 77 65 62 6b 69 74 2d 66 6f 6e 74 2d 73 6d 6f 6f 74 68 69 6e 67 3a 20 61 6e 74 69 61 6c 69 61 73 65 64 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 53 61 6e 73 2d 53 65 72 69 66 3b 7d 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 62 37 33 62 33 63 3b 20 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 33 33 3b 20 6c 65 74 74 65 72 2d 73 70 61 63 69 6e 67 3a 20 2d 30 2e 31 70 78 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 33 30 30 3b 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 73 74 79 6c 65 3a 20 6e 6f 72 6d 61 6c 3b 20 66 6f 6e 74 2d 73 74 72 65 74 63 68 3a 20 6e 6f 72 6d 61 6c 3b 7d 2e 69 63 6f 6e 2d 77 61 72 6e 69 6e 67 7b 77 69 64 74 68 3a 20 37 32 70 78 3b 7d 2e 74 69 74 6c 65 7b 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 34 38 70 78 3b 7d 64 69 76 7b 6d 61 78 2d 77 69 64 74 68 3a 20 38 30 30 70 78 3b 7d 61 2c 20 61 3a 68 6f 76 65 72 2c 20 61 3a 76 69 73 69 74 65 64 7b 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 20 75 6e 64 65 72 6c 69 6e 65 3b 7d 2e 6d 65 73 73 61 67 65 7b 66 6f 6e 74 2d 73 69 7a 65 3a 20 32 30 70 78 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 34 3b 20 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 31 36 70 78 3b 20 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 20 34 38 70 78 3b 7d 2e 6d 65 73 73 61 67 65 20 73 74 72 6f 6e 67 7b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 36 30 30 3b 20 6c 65 74 74 65 72 2d 73 70 61 Data Ascii: <html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff
      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
      Source: unknownNetwork traffic detected: HTTP traffic on port 57255 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57255
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: classification engineClassification label: mal48.win@16/2@8/6
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=2020,i,13513465400319421349,3291854257070266711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://rebrand.ly/dfi21fe"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=2020,i,13513465400319421349,3291854257070266711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      1
      Process Injection
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Ingress Tool Transfer
      Traffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      http://rebrand.ly/dfi21fe100%Avira URL Cloudphishing
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      rebrand.ly
      15.197.137.111
      truefalse
        high
        www.google.com
        142.250.186.100
        truefalse
          high
          www.rebrandly.com
          18.66.102.21
          truefalse
            high
            NameMaliciousAntivirus DetectionReputation
            http://rebrand.ly/favicon.icofalse
              high
              http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151false
                high
                http://rebrand.ly/dfi21fefalse
                  high
                  https://www.rebrandly.com/not-foundfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    15.197.137.111
                    rebrand.lyUnited States
                    7430TANDEMUSfalse
                    18.66.102.21
                    www.rebrandly.comUnited States
                    3MIT-GATEWAYSUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.250.186.100
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    192.168.2.5
                    Joe Sandbox version:42.0.0 Malachite
                    Analysis ID:1590428
                    Start date and time:2025-01-14 01:36:00 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 58s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://rebrand.ly/dfi21fe
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal48.win@16/2@8/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.184.227, 142.250.74.206, 142.250.110.84, 172.217.23.110, 142.250.184.206, 142.250.185.206, 199.232.210.172, 23.50.108.3, 142.250.185.110, 142.250.186.174, 142.250.184.238, 142.250.81.238, 74.125.0.102, 216.58.206.67, 2.23.242.162, 4.175.87.197, 13.107.246.45
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com
                    • Not all processes where analyzed, report is missing behavior information
                    • VT rate limit hit for: http://rebrand.ly/dfi21fe
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with very long lines (2623), with no line terminators
                    Category:downloaded
                    Size (bytes):2623
                    Entropy (8bit):5.426888206506014
                    Encrypted:false
                    SSDEEP:48:oJ9wxqwzph0KVO9vnbnSOrLOwOzsdCZf/rHX7SafCUeOvjtDYd:oJ9Eqaph0WO9vnbnSOPOwOzu6/raU75G
                    MD5:403355A474FB4486CFD7297B6FE374F3
                    SHA1:B03228CDDA53F19F4EC05F2A391C42D7EEBB4688
                    SHA-256:74D48DF2CA3D871809AB8FFE35DC49CCDB979E54A8B1C01841910E30D41EED68
                    SHA-512:9318738AC55CAD59F5110FF0C296A2BBCF314B397DDCC56290EA873A2B81D53E5CD05C6BCE84343C29D0BEF550AAF7AB48E84F207BECEBBD6F5928A3870252D7
                    Malicious:false
                    Reputation:low
                    URL:http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151
                    Preview:<html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff; text-decoration: underline;}.message{font-size: 20px; line-height: 1.4; margin-top: 16px; margin-bottom: 48px;}.message strong{font-weight: 600; letter-spacing: normal;}.note{font-size: 15px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 16px;}.cta_rebrandly{margin-top: 125px;}p.cta_rebrandly span{border-radius: 4px; border: solid 1px #ffffff; padding: 8px 24px; text-decoration: none; -moz-transition: all .2s ease-in; -o-transition: all .2s ease-in; -webkit-transition: all .2s ease-in
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 14, 2025 01:36:45.667543888 CET49675443192.168.2.4173.222.162.32
                    Jan 14, 2025 01:36:55.276652098 CET49675443192.168.2.4173.222.162.32
                    Jan 14, 2025 01:37:00.033948898 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.033998013 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.035403967 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.035610914 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.035623074 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.686882973 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.687238932 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.687304020 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.688182116 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.688350916 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.689412117 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.689491034 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.744220972 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:00.744282007 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:00.791086912 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:02.027601957 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.027806044 CET4974180192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.032404900 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.032562017 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.032618999 CET804974115.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.032716036 CET4974180192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.032809019 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.037516117 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.536565065 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.538789034 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.543749094 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.654083014 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.654109001 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.654117107 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.654280901 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.765336990 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:02.770296097 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.867654085 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:02.889774084 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:02.889834881 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:02.890069962 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:02.890187979 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:02.890204906 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:02.918361902 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:03.608349085 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.608958006 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.608998060 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.610079050 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.610155106 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.617938042 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.618134022 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.618670940 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.669120073 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.669137001 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.729211092 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897003889 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897064924 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897088051 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897139072 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897170067 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897196054 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897221088 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897248030 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897248030 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897253990 CET4434974218.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.897269964 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897300959 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897939920 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.897960901 CET49742443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.920495987 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.920541048 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:03.920664072 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.920912981 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:03.920927048 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.657011986 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.657350063 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:04.657373905 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.658628941 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.658684015 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:04.659109116 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:04.659202099 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.659292936 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:04.699327946 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.728996038 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:04.729013920 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:04.789419889 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.338514090 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338543892 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338551998 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338582039 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338589907 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338593006 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338706017 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.338736057 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.338748932 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.338783026 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.404309034 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.422374010 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.422472000 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.422508955 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.422528028 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.422564030 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.422570944 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.422600031 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.422607899 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.428292990 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.428302050 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.428358078 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.428388119 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.428400993 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.428419113 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.428467989 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.492053032 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.492198944 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.512671947 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.512742996 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.512933016 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.512954950 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.512999058 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.513312101 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.513387918 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.513395071 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.513499022 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:05.513505936 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.513542891 CET4434974318.66.102.21192.168.2.4
                    Jan 14, 2025 01:37:05.513556004 CET49743443192.168.2.418.66.102.21
                    Jan 14, 2025 01:37:10.614051104 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:10.614206076 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:10.614281893 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:12.480633020 CET49737443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:37:12.480707884 CET44349737142.250.186.100192.168.2.4
                    Jan 14, 2025 01:37:37.032984972 CET5720153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:37.037941933 CET53572011.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:37.038017035 CET5720153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:37.038034916 CET5720153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:37.042942047 CET53572011.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:37.483192921 CET53572011.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:37.484141111 CET5720153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:37.489212990 CET53572011.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:37.489279985 CET5720153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:47.041780949 CET4974180192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:47.046787977 CET804974115.197.137.111192.168.2.4
                    Jan 14, 2025 01:37:47.869399071 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:37:47.874327898 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:38:00.089111090 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:00.089145899 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.089222908 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:00.089476109 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:00.089498043 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.741497993 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.741823912 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:00.741833925 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.742501020 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.742829084 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:00.742913961 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:00.790704966 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:01.822174072 CET4972380192.168.2.488.221.110.91
                    Jan 14, 2025 01:38:01.828428984 CET804972388.221.110.91192.168.2.4
                    Jan 14, 2025 01:38:01.828526020 CET4972380192.168.2.488.221.110.91
                    Jan 14, 2025 01:38:02.466996908 CET804974115.197.137.111192.168.2.4
                    Jan 14, 2025 01:38:02.467072964 CET4974180192.168.2.415.197.137.111
                    Jan 14, 2025 01:38:02.479882002 CET4974180192.168.2.415.197.137.111
                    Jan 14, 2025 01:38:02.484690905 CET804974115.197.137.111192.168.2.4
                    Jan 14, 2025 01:38:02.865678072 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:38:02.865727901 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:38:04.480055094 CET4974080192.168.2.415.197.137.111
                    Jan 14, 2025 01:38:04.484821081 CET804974015.197.137.111192.168.2.4
                    Jan 14, 2025 01:38:10.662928104 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:10.662966967 CET44357255142.250.186.100192.168.2.4
                    Jan 14, 2025 01:38:10.663022041 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:12.481442928 CET57255443192.168.2.4142.250.186.100
                    Jan 14, 2025 01:38:12.481453896 CET44357255142.250.186.100192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 14, 2025 01:36:55.912591934 CET53650351.1.1.1192.168.2.4
                    Jan 14, 2025 01:36:56.890233040 CET53641991.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:00.026413918 CET6138953192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:00.026542902 CET6334253192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:00.033029079 CET53633421.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:00.033086061 CET53613891.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:02.014589071 CET6199753192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:02.014889956 CET5820153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:02.024568081 CET53619971.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:02.024583101 CET53582011.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:02.870599031 CET6312853192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:02.870791912 CET6356553192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:02.888513088 CET53635651.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:02.889297962 CET53631281.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:03.901915073 CET6184153192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:03.902056932 CET5752853192.168.2.41.1.1.1
                    Jan 14, 2025 01:37:03.919693947 CET53575281.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:03.919962883 CET53618411.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:13.391096115 CET138138192.168.2.4192.168.2.255
                    Jan 14, 2025 01:37:14.003405094 CET53651841.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:32.987543106 CET53637581.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:37.032558918 CET53590461.1.1.1192.168.2.4
                    Jan 14, 2025 01:37:55.426527023 CET53635411.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Jan 14, 2025 01:37:00.026413918 CET192.168.2.41.1.1.10xe81eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:00.026542902 CET192.168.2.41.1.1.10x8ee9Standard query (0)www.google.com65IN (0x0001)false
                    Jan 14, 2025 01:37:02.014589071 CET192.168.2.41.1.1.10x4c7cStandard query (0)rebrand.lyA (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.014889956 CET192.168.2.41.1.1.10x30cbStandard query (0)rebrand.ly65IN (0x0001)false
                    Jan 14, 2025 01:37:02.870599031 CET192.168.2.41.1.1.10x99e0Standard query (0)www.rebrandly.comA (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.870791912 CET192.168.2.41.1.1.10xd12dStandard query (0)www.rebrandly.com65IN (0x0001)false
                    Jan 14, 2025 01:37:03.901915073 CET192.168.2.41.1.1.10x620Standard query (0)www.rebrandly.comA (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:03.902056932 CET192.168.2.41.1.1.10x8cdeStandard query (0)www.rebrandly.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Jan 14, 2025 01:37:00.033029079 CET1.1.1.1192.168.2.40x8ee9No error (0)www.google.com65IN (0x0001)false
                    Jan 14, 2025 01:37:00.033086061 CET1.1.1.1192.168.2.40xe81eNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.024568081 CET1.1.1.1192.168.2.40x4c7cNo error (0)rebrand.ly15.197.137.111A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.024568081 CET1.1.1.1192.168.2.40x4c7cNo error (0)rebrand.ly3.33.143.57A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.889297962 CET1.1.1.1192.168.2.40x99e0No error (0)www.rebrandly.com18.66.102.21A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.889297962 CET1.1.1.1192.168.2.40x99e0No error (0)www.rebrandly.com18.66.102.102A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.889297962 CET1.1.1.1192.168.2.40x99e0No error (0)www.rebrandly.com18.66.102.111A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:02.889297962 CET1.1.1.1192.168.2.40x99e0No error (0)www.rebrandly.com18.66.102.127A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:03.919962883 CET1.1.1.1192.168.2.40x620No error (0)www.rebrandly.com18.66.102.21A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:03.919962883 CET1.1.1.1192.168.2.40x620No error (0)www.rebrandly.com18.66.102.102A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:03.919962883 CET1.1.1.1192.168.2.40x620No error (0)www.rebrandly.com18.66.102.111A (IP address)IN (0x0001)false
                    Jan 14, 2025 01:37:03.919962883 CET1.1.1.1192.168.2.40x620No error (0)www.rebrandly.com18.66.102.127A (IP address)IN (0x0001)false
                    • rebrand.ly
                      • www.rebrandly.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44974015.197.137.111803104C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Jan 14, 2025 01:37:02.032809019 CET432OUTGET /dfi21fe HTTP/1.1
                    Host: rebrand.ly
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Jan 14, 2025 01:37:02.536565065 CET230INHTTP/1.1 302 Found
                    Date: Tue, 14 Jan 2025 00:37:02 GMT
                    Content-Length: 0
                    Connection: keep-alive
                    Location: http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151
                    Engine: Rebrandly.redirect, version 2.1
                    Jan 14, 2025 01:37:02.538789034 CET482OUTGET /dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151 HTTP/1.1
                    Host: rebrand.ly
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Jan 14, 2025 01:37:02.654083014 CET1236INHTTP/1.1 404 Not Found
                    Date: Tue, 14 Jan 2025 00:37:02 GMT
                    Content-Type: text/html
                    Content-Length: 2623
                    Connection: keep-alive
                    Server: AmazonS3
                    Accept-Ranges: bytes
                    Age: 42777
                    ETag: "403355a474fb4486cfd7297b6fe374f3"
                    Last-Modified: Thu, 17 Feb 2022 13:49:52 GMT
                    Via: 1.1 3ebe5e903d733a5e00724b1dfdba02bc.cloudfront.net (CloudFront)
                    Engine: Rebrandly.redirect, version 2.1
                    x-amz-server-side-encryption: AES256
                    x-amz-version-id: 0Ou37jKCUePL5aO7kLp5FP9Ly.sMxBw9
                    X-Cache: Error from cloudfront
                    X-Amz-Cf-Pop: IAD79-C3
                    X-Amz-Cf-Id: LZbMhgvK6vuz4XKrMLqhY4RlI9O5MgAc6MJcK8O93sFXgonFyXOGhg==
                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 20 3c 73 74 79 6c 65 3e 68 74 6d 6c 2c 20 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 20 30 3b 20 70 61 64 64 69 6e 67 3a 20 30 3b 20 2d 77 65 62 6b 69 74 2d 66 6f 6e 74 2d 73 6d 6f 6f 74 68 69 6e 67 3a 20 61 6e 74 69 61 6c 69 61 73 65 64 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 53 61 6e 73 2d 53 65 72 69 66 3b 7d 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 62 37 33 62 33 63 3b 20 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 33 33 3b 20 6c 65 74 74 65 72 2d 73 70 61 63 69 6e 67 3a 20 2d 30 2e 31 70 78 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 33 30 30 3b 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 20 66 6f 6e 74 2d 73 74 79 6c 65 3a 20 6e 6f [TRUNCATED]
                    Data Ascii: <html><head> <style>html, body{margin: 0; padding: 0; -webkit-font-smoothing: antialiased; font-family: Helvetica, Arial, Sans-Serif;}body{background-color: #b73b3c; color: #ffffff; line-height: 1.33; letter-spacing: -0.1px; text-align: center; font-weight: 300; display: flex; align-items: center; justify-content: center; font-style: normal; font-stretch: normal;}.icon-warning{width: 72px;}.title{margin-top: 48px;}div{max-width: 800px;}a, a:hover, a:visited{color: #ffffff; text-decoration: underline;}.message{font-size: 20px; line-height: 1.4; margin-top: 16px; margin-bottom: 48px;}.message strong{font-weight: 600; letter-spa
                    Jan 14, 2025 01:37:02.654109001 CET1236INData Raw: 63 69 6e 67 3a 20 6e 6f 72 6d 61 6c 3b 7d 2e 6e 6f 74 65 7b 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 35 70 78 3b 20 77 68 69 74 65 2d 73 70 61 63 65 3a 20 6e 6f 77 72 61 70 3b 20 6f 76 65 72 66 6c 6f 77 3a 20 68 69 64 64 65 6e 3b 20 74 65 78 74 2d 6f
                    Data Ascii: cing: normal;}.note{font-size: 15px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 16px;}.cta_rebrandly{margin-top: 125px;}p.cta_rebrandly span{border-radius: 4px; border: solid 1px #ffffff; padding: 8px 24px;
                    Jan 14, 2025 01:37:02.654117107 CET754INData Raw: 41 77 65 6b 30 7a 4e 69 41 31 4e 32 45 7a 49 44 4d 67 4d 43 41 78 49 44 41 67 4d 43 30 32 49 44 4d 67 4d 79 41 77 49 44 41 67 4d 43 41 77 49 44 5a 36 62 54 41 74 4d 54 4a 68 4d 79 41 7a 49 44 41 67 4d 43 41 77 49 44 4d 74 4d 31 59 7a 4d 47 45 7a
                    Data Ascii: Awek0zNiA1N2EzIDMgMCAxIDAgMC02IDMgMyAwIDAgMCAwIDZ6bTAtMTJhMyAzIDAgMCAwIDMtM1YzMGEzIDMgMCAwIDAtNiAwdjEyYTMgMyAwIDAgMCAzIDN6Ii8+Cjwvc3ZnPgo="> <h1 class="title">Stop! Deceptive page ahead!</h1> <div class="message"> This short URL has been disab
                    Jan 14, 2025 01:37:02.765336990 CET421OUTGET /favicon.ico HTTP/1.1
                    Host: rebrand.ly
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Referer: http://rebrand.ly/dfi21fe?rb.routing.mode=proxy&rb.routing.signature=248151
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Jan 14, 2025 01:37:02.867654085 CET190INHTTP/1.1 302 Found
                    Date: Tue, 14 Jan 2025 00:37:02 GMT
                    Content-Length: 0
                    Connection: keep-alive
                    Location: https://www.rebrandly.com/not-found
                    Engine: Rebrandly.redirect, version 2.1
                    Jan 14, 2025 01:37:47.869399071 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44974115.197.137.111803104C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Jan 14, 2025 01:37:47.041780949 CET6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44974218.66.102.214433104C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-01-14 00:37:03 UTC449OUTGET /not-found HTTP/1.1
                    Host: www.rebrandly.com
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: cross-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: http://rebrand.ly/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2025-01-14 00:37:03 UTC829INHTTP/1.1 200 OK
                    Content-Type: text/html
                    Content-Length: 73703
                    Connection: close
                    Date: Tue, 14 Jan 2025 00:37:04 GMT
                    Last-Modified: Tue, 07 Jan 2025 14:32:43 GMT
                    x-amz-server-side-encryption: AES256
                    Cache-Control: no-cache, no-store, must-revalidate
                    Accept-Ranges: bytes
                    Server: AmazonS3
                    ETag: "aa87ff427d04890f5d59f20a6d2415ae"
                    Vary: Accept-Encoding
                    X-Cache: Hit from cloudfront
                    Via: 1.1 21c2c1b3872c539a34b64bcf45f4054c.cloudfront.net (CloudFront)
                    X-Amz-Cf-Pop: FRA56-P2
                    Alt-Svc: h3=":443"; ma=86400
                    X-Amz-Cf-Id: ISQ5ft8yj58HnypORxn9NPUS08-tbcZr_gEcVQ8S9uVb9udZurFhfg==
                    X-XSS-Protection: 1; mode=block
                    X-Frame-Options: DENY
                    Content-Security-Policy: frame-ancestors 'self'; upgrade-insecure-requests;
                    X-Content-Type-Options: nosniff
                    Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                    2025-01-14 00:37:03 UTC15555INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 68 74 74 70 2d 65 71 75 69 76 3d 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 20 68 74 74 70 2d 65 71 75 69 76 3d 78 2d 75 61 2d 63 6f 6d 70 61 74 69 62 6c 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 52 65 62 72 61 6e 64 6c 79 20 69 73 20 74 68 65 20 66 72 65 65 20 55 52 4c 20 53 68 6f 72 74 65 6e 65 72 20 50 6c 61 74 66 6f 72 6d 20 77 69 74 68 20 63 75 73 74 6f 6d 20 64 6f 6d 61 69 6e 73 20 74 6f 20 73 68 6f 72 74 65 6e 20 61 20 6c 6f 6e 67 20 6c 69 6e 6b 2e 20
                    Data Ascii: <!DOCTYPE html><html lang=en><head><meta content="text/html; charset=utf-8" http-equiv=Content-Type><meta content="ie=edge" http-equiv=x-ua-compatible><meta content="Rebrandly is the free URL Shortener Platform with custom domains to shorten a long link.


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44974318.66.102.214433104C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-01-14 00:37:04 UTC350OUTGET /not-found HTTP/1.1
                    Host: www.rebrandly.com
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: */*
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: cors
                    Sec-Fetch-Dest: empty
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2025-01-14 00:37:05 UTC830INHTTP/1.1 200 OK
                    Content-Type: text/html
                    Content-Length: 73703
                    Connection: close
                    Date: Tue, 14 Jan 2025 00:37:06 GMT
                    Last-Modified: Tue, 07 Jan 2025 14:32:43 GMT
                    x-amz-server-side-encryption: AES256
                    Cache-Control: no-cache, no-store, must-revalidate
                    Accept-Ranges: bytes
                    Server: AmazonS3
                    ETag: "aa87ff427d04890f5d59f20a6d2415ae"
                    Vary: Accept-Encoding
                    X-Cache: Miss from cloudfront
                    Via: 1.1 80a51c83bb9479e2a3aa1ea59b366458.cloudfront.net (CloudFront)
                    X-Amz-Cf-Pop: FRA56-P2
                    Alt-Svc: h3=":443"; ma=86400
                    X-Amz-Cf-Id: QYvi9GDG0tGLwClNGS4btzi8_6V1725DOtS8f-vgzOTcjr-BeT7INQ==
                    X-XSS-Protection: 1; mode=block
                    X-Frame-Options: DENY
                    Content-Security-Policy: frame-ancestors 'self'; upgrade-insecure-requests;
                    X-Content-Type-Options: nosniff
                    Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                    2025-01-14 00:37:05 UTC15554INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 20 68 74 74 70 2d 65 71 75 69 76 3d 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 20 68 74 74 70 2d 65 71 75 69 76 3d 78 2d 75 61 2d 63 6f 6d 70 61 74 69 62 6c 65 3e 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 22 52 65 62 72 61 6e 64 6c 79 20 69 73 20 74 68 65 20 66 72 65 65 20 55 52 4c 20 53 68 6f 72 74 65 6e 65 72 20 50 6c 61 74 66 6f 72 6d 20 77 69 74 68 20 63 75 73 74 6f 6d 20 64 6f 6d 61 69 6e 73 20 74 6f 20 73 68 6f 72 74 65 6e 20 61 20 6c 6f 6e 67 20 6c 69 6e 6b 2e 20
                    Data Ascii: <!DOCTYPE html><html lang=en><head><meta content="text/html; charset=utf-8" http-equiv=Content-Type><meta content="ie=edge" http-equiv=x-ua-compatible><meta content="Rebrandly is the free URL Shortener Platform with custom domains to shorten a long link.
                    2025-01-14 00:37:05 UTC436INData Raw: 72 2d 77 68 69 74 65 29 3b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 31 30 70 78 3b 70 61 64 64 69 6e 67 3a 31 36 70 78 20 32 30 70 78 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 30 70 78 7d 2e 5f 62 6f 74 74 6f 6d 5f 63 6f 6e 74 61 69 6e 65 72 5f 31 63 79 6b 32 5f 33 33 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 77 68 69 74 65 2d 73 70 61 63 65 3a 62 72 65 61 6b 2d 73 70 61 63 65 73 3b 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 34 30 70 78 3b 70 61 64 64 69 6e 67 2d 72 69 67 68 74 3a 34 30 70 78 7d 2e 5f 62 6f 74 74 6f 6d 5f 63 6f 6e 74 61 69 6e 65 72 5f 31 63 79 6b 32 5f 33 33 20 73 70 61 6e 7b 74 65 78 74 2d 61 6c 69 67 6e 3a 63
                    Data Ascii: r-white);border-radius:10px;padding:16px 20px;margin-bottom:10px}._bottom_container_1cyk2_33{display:flex;justify-content:center;align-items:center;white-space:break-spaces;padding-left:40px;padding-right:40px}._bottom_container_1cyk2_33 span{text-align:c
                    2025-01-14 00:37:05 UTC970INData Raw: 77 68 69 74 65 2d 73 70 61 63 65 3a 6e 6f 77 72 61 70 7d 2e 5f 62 6f 74 74 6f 6d 5f 63 6f 6e 74 61 69 6e 65 72 5f 31 63 79 6b 32 5f 33 33 20 2e 5f 62 6f 74 74 6f 6d 5f 63 6f 6e 74 61 69 6e 65 72 5f 73 61 6c 65 73 5f 6d 6f 64 61 6c 5f 31 63 79 6b 32 5f 34 36 3a 68 6f 76 65 72 7b 63 6f 6c 6f 72 3a 76 61 72 28 2d 2d 63 6f 6c 6f 72 2d 67 72 65 79 2d 36 30 30 29 7d 40 6d 65 64 69 61 20 28 6d 61 78 2d 77 69 64 74 68 3a 31 30 32 33 70 78 29 7b 2e 5f 74 69 74 6c 65 5f 31 63 79 6b 32 5f 32 30 7b 66 6f 6e 74 2d 73 69 7a 65 3a 33 34 70 78 7d 7d 40 6d 65 64 69 61 20 28 6d 61 78 2d 77 69 64 74 68 3a 37 36 37 70 78 29 7b 2e 5f 67 72 69 64 5f 62 6f 78 5f 31 63 79 6b 32 5f 31 33 7b 67 72 69 64 2d 74 65 6d 70 6c 61 74 65 2d 63 6f 6c 75 6d 6e 73 3a 31 66 72 3b 67 61 70 3a
                    Data Ascii: white-space:nowrap}._bottom_container_1cyk2_33 ._bottom_container_sales_modal_1cyk2_46:hover{color:var(--color-grey-600)}@media (max-width:1023px){._title_1cyk2_20{font-size:34px}}@media (max-width:767px){._grid_box_1cyk2_13{grid-template-columns:1fr;gap:
                    2025-01-14 00:37:05 UTC12792INData Raw: 6f 6e 74 65 6e 74 20 2e 46 6f 72 6d 5f 5f 63 6f 6e 74 72 6f 6c 7b 66 6c 65 78 2d 67 72 6f 77 3a 31 7d 2e 51 52 43 6f 64 65 41 63 74 69 6f 6e 5f 5f 73 69 7a 65 7b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 73 70 61 63 65 2d 62 65 74 77 65 65 6e 7d 2e 51 52 43 6f 64 65 41 63 74 69 6f 6e 5f 5f 73 69 7a 65 3e 2e 54 61 67 3a 68 6f 76 65 72 7b 74 72 61 6e 73 69 74 69 6f 6e 3a 2e 33 73 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 76 61 72 28 2d 2d 63 6f 6c 6f 72 2d 62 6c 75 65 2d 36 30 30 29 21 69 6d 70 6f 72 74 61 6e 74 7d 2e 5f 6e 6f 74 69 66 69 63 61 74 69 6f 6e 5f 6f 75 70 63 6b 5f 32 7b 6d 61 78 2d 77 69 64 74 68 3a 33 34 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 66 69 78 65 64 3b 74 6f 70 3a 39 30 70 78 3b 72 69 67 68 74 3a 63 61 6c 63 28 28 31
                    Data Ascii: ontent .Form__control{flex-grow:1}.QRCodeAction__size{justify-content:space-between}.QRCodeAction__size>.Tag:hover{transition:.3s;background-color:var(--color-blue-600)!important}._notification_oupck_2{max-width:340px;position:fixed;top:90px;right:calc((1
                    2025-01-14 00:37:05 UTC16384INData Raw: 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 32 30 32 34 2d 30 38 2d 32 31 54 31 31 3a 34 30 3a 30 31 2e 30 38 39 5a 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 73 6c 75 67 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 73 6f 63 69 61 6c 2d 73 68 61 72 69 6e 67 26 71 75 6f 74 3b 5d 7d 5d 7d 5d 7d 5d 2c 26 71 75 6f 74 3b 69 6d 61 67 65 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71 75 6f 74 3b 64 61 74 61 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71 75 6f 74 3b 69 64 26 71 75 6f 74 3b 3a 5b 30 2c 33 37 35 5d 2c 26 71 75 6f 74 3b 61 74 74 72 69 62 75 74 65 73 26 71 75 6f 74 3b 3a 5b 30 2c 7b 26 71 75 6f 74 3b 6e 61 6d 65 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 69 63 2d 73 68 61 72 65 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 61 6c 74 65 72 6e 61 74 69 76 65 54
                    Data Ascii: t;:[0,&quot;2024-08-21T11:40:01.089Z&quot;],&quot;slug&quot;:[0,&quot;social-sharing&quot;]}]}]}],&quot;image&quot;:[0,{&quot;data&quot;:[0,{&quot;id&quot;:[0,375],&quot;attributes&quot;:[0,{&quot;name&quot;:[0,&quot;ic-share.svg&quot;],&quot;alternativeT
                    2025-01-14 00:37:05 UTC5640INData Raw: 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 65 78 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 6d 69 6d 65 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 69 6d 61 67 65 2f 73 76 67 2b 78 6d 6c 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 73 69 7a 65 26 71 75 6f 74 3b 3a 5b 30 2c 30 2e 34 39 5d 2c 26 71 75 6f 74 3b 75 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 72 65 62 72 61 6e 64 6c 79 2e 63 6f 6d 2f 69 63 5f 72 65 70 6f 72 74 73 5f 35 32 62 39 65 38 35 64 63 63 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 70 72 65 76 69 65 77 55 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 2c 26 71 75 6f 74 3b 70 72 6f 76 69 64 65 72 26 71 75 6f 74 3b 3a 5b
                    Data Ascii: quot;],&quot;ext&quot;:[0,&quot;.svg&quot;],&quot;mime&quot;:[0,&quot;image/svg+xml&quot;],&quot;size&quot;:[0,0.49],&quot;url&quot;:[0,&quot;https://cdn.rebrandly.com/ic_reports_52b9e85dcc.svg&quot;],&quot;previewUrl&quot;:[0,null],&quot;provider&quot;:[
                    2025-01-14 00:37:05 UTC12792INData Raw: 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 65 78 74 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 6d 69 6d 65 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 69 6d 61 67 65 2f 73 76 67 2b 78 6d 6c 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 73 69 7a 65 26 71 75 6f 74 3b 3a 5b 30 2c 30 2e 34 35 5d 2c 26 71 75 6f 74 3b 75 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 26 71 75 6f 74 3b 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 72 65 62 72 61 6e 64 6c 79 2e 63 6f 6d 2f 69 63 5f 72 6f 75 74 65 5f 37 34 36 61 34 33 32 63 32 31 2e 73 76 67 26 71 75 6f 74 3b 5d 2c 26 71 75 6f 74 3b 70 72 65 76 69 65 77 55 72 6c 26 71 75 6f 74 3b 3a 5b 30 2c 6e 75 6c 6c 5d 2c 26 71 75 6f 74 3b 70 72 6f 76 69 64 65 72 26 71 75 6f 74 3b 3a 5b 30 2c
                    Data Ascii: quot;],&quot;ext&quot;:[0,&quot;.svg&quot;],&quot;mime&quot;:[0,&quot;image/svg+xml&quot;],&quot;size&quot;:[0,0.45],&quot;url&quot;:[0,&quot;https://cdn.rebrandly.com/ic_route_746a432c21.svg&quot;],&quot;previewUrl&quot;:[0,null],&quot;provider&quot;:[0,
                    2025-01-14 00:37:05 UTC9135INData Raw: 33 38 30 36 5a 4d 32 38 33 2e 32 39 31 20 34 31 2e 36 31 31 38 56 35 36 2e 34 37 31 33 48 32 38 33 2e 32 38 37 56 36 38 2e 36 31 39 39 48 32 39 34 2e 30 39 31 56 33 38 2e 30 34 31 33 43 32 39 34 2e 30 39 31 20 32 36 2e 33 36 38 38 20 32 38 36 2e 32 38 20 31 38 2e 36 35 34 38 20 32 37 34 2e 36 30 37 20 31 38 2e 36 35 34 38 43 32 36 37 2e 36 36 35 20 31 38 2e 36 35 34 38 20 32 36 31 2e 39 37 20 32 31 2e 32 35 39 39 20 32 35 38 2e 30 31 36 20 32 36 2e 30 38 32 33 56 31 39 2e 34 31 37 34 48 32 34 37 2e 32 31 31 56 36 38 2e 36 32 34 33 48 32 35 38 2e 30 31 36 56 34 31 2e 34 31 37 39 43 32 35 38 2e 30 31 36 20 33 34 2e 31 38 38 37 20 32 36 33 2e 32 32 36 20 32 39 2e 30 37 35 34 20 32 37 31 2e 30 34 31 20 32 39 2e 30 37 35 34 43 32 37 38 2e 34 36 39 20 32 39 2e
                    Data Ascii: 3806ZM283.291 41.6118V56.4713H283.287V68.6199H294.091V38.0413C294.091 26.3688 286.28 18.6548 274.607 18.6548C267.665 18.6548 261.97 21.2599 258.016 26.0823V19.4174H247.211V68.6243H258.016V41.4179C258.016 34.1887 263.226 29.0754 271.041 29.0754C278.469 29.


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:19:36:50
                    Start date:13/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:19:36:54
                    Start date:13/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=2020,i,13513465400319421349,3291854257070266711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:19:37:01
                    Start date:13/01/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://rebrand.ly/dfi21fe"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly