Edit tour

Windows Analysis Report
https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%

Overview

General Information

Sample URL:https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%
Analysis ID:1648609
Infos:

Detection

HTMLPhisher
Score:48
Range:0 - 100
Confidence:100%

Signatures

Yara detected BlockedWebSite
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2804 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2292,i,17352436165678199142,10092777188710425798,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2492 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dropped/chromecache_52JoeSecurity_BlockedWebSiteYara detected BlockedWebSiteJoe Security
    SourceRuleDescriptionAuthorStrings
    0.0.pages.csvJoeSecurity_BlockedWebSiteYara detected BlockedWebSiteJoe Security
      No Sigma rule has matched
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      Phishing

      barindex
      Source: Yara matchFile source: 0.0.pages.csv, type: HTML
      Source: Yara matchFile source: dropped/chromecache_52, type: DROPPED
      Source: unknownHTTPS traffic detected: 142.251.40.196:443 -> 192.168.2.4:49723 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.208.28:443 -> 192.168.2.4:49726 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.208.28:443 -> 192.168.2.4:49727 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.209.28:443 -> 192.168.2.4:49737 version: TLS 1.2
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0 HTTP/1.1Host: usg02.safelinks.protection.office365.usConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /Content/Scripts/safelinksv2.css HTTP/1.1Host: usg02.safelinks.protection.office365.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /Content/Scripts/site.js HTTP/1.1Host: usg02.safelinks.protection.office365.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /Content/images/cross.png HTTP/1.1Host: usg02.safelinks.protection.office365.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /Content/images/cross.png HTTP/1.1Host: usg02.safelinks.protection.office365.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: usg02.safelinks.protection.office365.us
      Source: chromecache_52.3.drString found in binary or memory: https://links.daily.investingskeeper.com/track?uid=a3279f8b-b292-438c-a320-cc20f4c87589&txnid=4d
      Source: chromecache_52.3.drString found in binary or memory: https://usg02.safelinks.protection.office365.us
      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
      Source: unknownHTTPS traffic detected: 142.251.40.196:443 -> 192.168.2.4:49723 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.208.28:443 -> 192.168.2.4:49726 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.208.28:443 -> 192.168.2.4:49727 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 23.103.209.28:443 -> 192.168.2.4:49737 version: TLS 1.2
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir2804_784016560Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir2804_784016560Jump to behavior
      Source: classification engineClassification label: mal48.phis.win@21/9@6/4
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2292,i,17352436165678199142,10092777188710425798,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2492 /prefetch:3
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2292,i,17352436165678199142,10092777188710425798,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2492 /prefetch:3Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      1
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      File Deletion
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
      Ingress Tool Transfer
      Traffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 signatures2 2 Behavior Graph ID: 1648609 URL: https://usg02.safelinks.pro... Startdate: 26/03/2025 Architecture: WINDOWS Score: 48 22 Yara detected BlockedWebSite 2->22 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.4, 138, 443, 49594 unknown unknown 6->14 11 chrome.exe 6->11         started        process5 dnsIp6 16 usg02.safelinks.protection.office365.us 23.103.208.28, 443, 49726, 49727 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 11->16 18 23.103.209.28, 443, 49737 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 11->18 20 www.google.com 142.251.40.196, 443, 49723, 49743 GOOGLEUS United States 11->20

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=00%Avira URL Cloudsafe
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      https://links.daily.investingskeeper.com/track?uid=a3279f8b-b292-438c-a320-cc20f4c87589&txnid=4d0%Avira URL Cloudsafe

      Download Network PCAP: filteredfull

      NameIPActiveMaliciousAntivirus DetectionReputation
      usg02.safelinks.protection.office365.us
      23.103.208.28
      truefalse
        high
        www.google.com
        142.251.40.196
        truefalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://usg02.safelinks.protection.office365.us/Content/Scripts/safelinksv2.cssfalse
            high
            https://usg02.safelinks.protection.office365.us/Content/images/cross.pngfalse
              high
              https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0false
                high
                https://usg02.safelinks.protection.office365.us/Content/Scripts/site.jsfalse
                  high
                  NameSourceMaliciousAntivirus DetectionReputation
                  https://links.daily.investingskeeper.com/track?uid=a3279f8b-b292-438c-a320-cc20f4c87589&txnid=4dchromecache_52.3.drfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://usg02.safelinks.protection.office365.uschromecache_52.3.drfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    23.103.209.28
                    unknownUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    23.103.208.28
                    usg02.safelinks.protection.office365.usUnited States
                    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                    142.251.40.196
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:42.0.0 Malachite
                    Analysis ID:1648609
                    Start date and time:2025-03-26 01:56:42 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 10s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%3A00%3A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%3A%2F%2Fclick.tracking.investingskeeper.com%2F67c9843e0f3b707c79a6b65c%3Femail%3Dlinden.blue%2540ga.com%26domain%3D035IK%26type%3DB%26product%3DAYGT3JS2%26utm_campaign%3Dik_r-24-3-aygt3js2-yahoo_all%26utm_source%3Dblueshift%26utm_medium%3Demail%26utm_content%3Dik_r-template-2&data=05|02|linden.blue%40ga.com|b400af556efd4c2a03ac08dd6b24dfdb|05e53887e4b3459587f73ae79f0e723e|0|0|638784528308949376|Unknown|TWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D|0|||&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:20
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal48.phis.win@21/9@6/4
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.251.41.3, 142.251.40.110, 142.251.40.238, 64.233.180.84, 142.250.81.238, 142.250.176.206, 23.203.176.221, 199.232.214.172, 142.250.72.110, 142.250.80.110, 142.251.32.110, 142.250.80.78, 142.250.176.195, 142.251.40.206, 142.250.72.99, 184.31.69.3, 4.245.163.56
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, update.googleapis.com, clients.l.google.com, c.pki.goog
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenFile calls found.
                    • VT rate limit hit for: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&amp;data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMi
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with very long lines (3730), with CRLF line terminators
                    Category:downloaded
                    Size (bytes):6481
                    Entropy (8bit):5.9837161374056524
                    Encrypted:false
                    SSDEEP:96:qE6+WMS85j6dEKE7WzVDEJ3cG3pJjzpekmGbsMJpZmu7VvC68d4gC4vr:V6ZMSJ+7SzWJ3D5Nzpekdb1Jn1ZqR2Ir
                    MD5:9D0D75CBB0196F64A50E88E68DCF5FF2
                    SHA1:7F56EE90FC68F9621610BA182F5C0A614B343EAD
                    SHA-256:E52A742B837BF9DC8127AC9BE5B04A72037834E031D2EE224E3092DAA98D08EE
                    SHA-512:2059BD2D3787214E59E95438586565F887489560E32D2D1C2E562F5DAC510BBCEC84B83658DB0A13A4AA6409A5036DDDF8DBEAE2A91FBCEDF3F807528521E662
                    Malicious:false
                    Reputation:low
                    URL:https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0
                    Preview:<!doctype html>..<html>..<head>.. <meta charset="UTF-8">.. <title>Microsoft Defender for Office 365</title>.. <meta name="referrer" content="same-origin" />.. <meta name="robots" content="noindex,nofollow" />.. <link rel="icon" href="data:,">.... <base href="https://usg02.safelinks.protection.office365.us">.... <link href="/Content/Scripts/safelinksv2.css" rel="stylesheet" />.. <script src="/Content/Scripts/site.js" type="text/javascript"></script>..</head>..<body>.. <div id="header_container_blocked">.. <div id="header">.. <div id="icon"><img src="/Content/images/cross.png" alt="" height="100" width="94"></div>.. <h1>.. This website is classified as malicious... </h1>.. </div>.. </div>.. <div id="recommendation_container">.. <div id="recommendation">.. <h2>Opening this website might not be safe.</h2>.. <div id="url">.. <p>..
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:PNG image data, 186 x 200, 8-bit/color RGBA, non-interlaced
                    Category:downloaded
                    Size (bytes):25664
                    Entropy (8bit):4.972505404550475
                    Encrypted:false
                    SSDEEP:384:OXE05KiOBf35OPGJulcJBzzdtKUmpZKfWve:E35Ki7PGJNJBZOpZKeve
                    MD5:FF4FEDB556605288FEC259EE6B8D5981
                    SHA1:BBC525AB65E54999044F14FF8F31CF25EEDB7754
                    SHA-256:2809B6F62DC341D238F02C33C7347A7BA714F10B6F075BDD39A1CD7C68CE9807
                    SHA-512:9EAE6F8D1822A1EF91B909B0D6A8826BFB323BD34FA76FBF0A2DCA99B5F580BA09173ECD2068F393979EBAE248BF5FF1FC592C5D43D5EEB33E0EC6DDE93E8349
                    Malicious:false
                    Reputation:low
                    URL:https://usg02.safelinks.protection.office365.us/Content/images/cross.png
                    Preview:.PNG........IHDR............._..;....pHYs...%...%.IR$....OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:PNG image data, 186 x 200, 8-bit/color RGBA, non-interlaced
                    Category:dropped
                    Size (bytes):25664
                    Entropy (8bit):4.972505404550475
                    Encrypted:false
                    SSDEEP:384:OXE05KiOBf35OPGJulcJBzzdtKUmpZKfWve:E35Ki7PGJNJBZOpZKeve
                    MD5:FF4FEDB556605288FEC259EE6B8D5981
                    SHA1:BBC525AB65E54999044F14FF8F31CF25EEDB7754
                    SHA-256:2809B6F62DC341D238F02C33C7347A7BA714F10B6F075BDD39A1CD7C68CE9807
                    SHA-512:9EAE6F8D1822A1EF91B909B0D6A8826BFB323BD34FA76FBF0A2DCA99B5F580BA09173ECD2068F393979EBAE248BF5FF1FC592C5D43D5EEB33E0EC6DDE93E8349
                    Malicious:false
                    Reputation:low
                    Preview:.PNG........IHDR............._..;....pHYs...%...%.IR$....OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):3932
                    Entropy (8bit):5.202197618496175
                    Encrypted:false
                    SSDEEP:96:W1nWD5QBnuxm32TPv1YyZvtcpcJcLCmzYzMz4ChX5xQFMXpSgfsHjrAwn:MmmqvWCiLfxpSgfsHjrAwn
                    MD5:BBAD95C4A0BE4E5775B7D5B409FBF602
                    SHA1:FAD598750B15C207DFEF6E1FEA3C072BAEAC2B66
                    SHA-256:41F78D15AE18C36B84C819D9AF3511C342C180F0ABA8F91DC1CCF4046B56B308
                    SHA-512:4006994F240E4DAB7134F1B716E51E4FFC0DD495EAF3269165FB0C27D89B2F19063AF17086553B39507199D62DBCD8BA6F07F34770BCAF15C40CF5EF06419631
                    Malicious:false
                    Reputation:low
                    URL:https://usg02.safelinks.protection.office365.us/Content/Scripts/safelinksv2.css
                    Preview:@charset "UTF-8";../* CSS Document */....body{...margin:0px;...padding:0px;..}....div{.. text-align:left;..}....#recommendation_container{...width:100%;..}....#icon img {...margin-left: 40px;...margin-top: 45px;..}....#url {height: 32px;..background-color: #f4f4f4;..margin-left: 40px;..margin-right: 40px;..margin-bottom: 20px;..margin-top: 0px;..font-family: Segoe, "Segoe UI", "DejaVu Sans", "Trebuchet MS", Verdana, "sans-serif";..display: inline-block;..}....#url p {...margin:4px 12px;..}......#close {height: 32px;..background-color: #0078d7;..margin-left: 40px;..margin-right:40px;..margin-top:20px;..padding: 4px 12px 8px 12px;..font-family: Segoe, "Segoe UI", "DejaVu Sans", "Trebuchet MS", Verdana, "sans-serif";..width: auto;..display: inline-block;..color: #fff;..border: 0;...font-size:100%;..}....#text {...margin-left:40px;...margin-right: 40px;...margin-top: 0px;...font-family: Segoe, "Segoe UI", "DejaVu Sans", "Trebuchet MS", Verdana, "sans-serif";..}....#tips {...margin-left:
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with CRLF line terminators
                    Category:downloaded
                    Size (bytes):1588
                    Entropy (8bit):5.174121809218917
                    Encrypted:false
                    SSDEEP:48:9pZigAOvzbYdvG2AumPBqykF1KdpwGFKcjeA5mkxofP:piFVmPBq/OI9GGP
                    MD5:3AF1FDB9A3F664A6683D212F4787733A
                    SHA1:59063D49B723A1988236C8D39C2804C6EBC5FF95
                    SHA-256:A9CE4840FF0D613B456081DEA64E46EB717A1F8BFA5AFB05D3BD058F294E416C
                    SHA-512:F8872E0C875BE6037C14480630E461FC1ADFA2049DB03BAE5D8CB6B320A2C084D4B266AEB02E24009B4BA84821E216690CA875B165164447FE8329B48C9E261F
                    Malicious:false
                    Reputation:low
                    URL:https://usg02.safelinks.protection.office365.us/Content/Scripts/site.js
                    Preview:window.onload = function OnLoadHandler(){...if (window.history.length <= 1) {....document.getElementById("close").style.display = "none";...}..}....var theme = null;..try {.. (function (URLSearchParams, str) {.. if (!new URLSearchParams(window.location.search).get(str)){....throw URLSearchParams;...}....var urlParams = new URLSearchParams(window.location.search);....if (urlParams.has(str)){.....theme = String(urlParams.get(str));....}.. }(URLSearchParams, "theme"));..} catch(URLSearchParams){...var params = {}...var parts = window.location.search.substring(1).split('&');...for (var i = 0; i < parts.length; i++) {....var val = parts[i].split('=');....if (!val[0]) continue;....params[val[0]] = val[1] || true;...}...theme = params["theme"];...}....// Load theme specific css..if (theme === "dark"){...AddCSS("Safelinksv2-dark.css");..}..else if (theme === "contrast"){...AddCSS("Safelinksv2-highcontrast.css")..}....// Add CSS based on theme..function AddCSS(fileName){... var ss = docume
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 104
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Mar 26, 2025 01:57:37.284415007 CET49680443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:37.799932003 CET4968180192.168.2.42.17.190.73
                    Mar 26, 2025 01:57:40.912554979 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:41.221775055 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:41.831270933 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:43.034399986 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:45.505126953 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:46.893248081 CET49680443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:47.408875942 CET4968180192.168.2.42.17.190.73
                    Mar 26, 2025 01:57:49.674515963 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:49.806052923 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:49.806122065 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:49.806195021 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:49.806338072 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:49.806355953 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:49.987024069 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:50.010118008 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:50.010195971 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:50.011363029 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:50.011380911 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:50.011642933 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:50.065140009 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:57:50.315160990 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:50.596415043 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:51.802324057 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:51.818700075 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.818734884 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:51.818799019 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.819020033 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.819036961 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:51.819386005 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.819469929 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:51.819614887 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.819722891 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:51.819746971 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.155713081 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.155786037 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:52.155991077 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.156070948 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:52.157617092 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:52.157632113 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.158128977 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.158433914 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:52.158478975 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.160222054 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:52.160228968 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.160629034 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:52.208394051 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:54.210784912 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:55.763952017 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.767137051 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.767184973 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.854223013 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.855232954 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.855310917 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.855837107 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.856218100 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.856236935 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.856298923 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.856347084 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.856405020 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.859385967 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.859424114 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:55.859462976 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.859482050 CET49710443192.168.2.4204.79.197.222
                    Mar 26, 2025 01:57:55.945647955 CET44349710204.79.197.222192.168.2.4
                    Mar 26, 2025 01:57:57.313010931 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.313066959 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.313152075 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.313183069 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.313235998 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.313241005 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.313292027 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.314929008 CET49727443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.314941883 CET4434972723.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.354618073 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.354650021 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.354724884 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.354851007 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.354968071 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.355129957 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.355148077 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.471575022 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.471601963 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.471709967 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.471746922 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.471913099 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.475681067 CET49726443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.475699902 CET4434972623.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.478243113 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.478274107 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.478751898 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.478794098 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.478799105 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.676625013 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.678967953 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.679008007 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.682390928 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.682405949 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.796504021 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.796526909 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.796629906 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.796629906 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.796746969 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.800978899 CET49732443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.801001072 CET4434973223.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.802578926 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.844333887 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.909935951 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.909948111 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:57.918060064 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:57.918109894 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148669958 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148734093 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148756981 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148798943 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148814917 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.148833036 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148842096 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148855925 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.148953915 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.148953915 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.148953915 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.148988008 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.149014950 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.149024010 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.149144888 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.149152040 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.149199009 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.149322987 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.149518967 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.153381109 CET49735443192.168.2.423.103.208.28
                    Mar 26, 2025 01:57:58.153403997 CET4434973523.103.208.28192.168.2.4
                    Mar 26, 2025 01:57:58.446722031 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.446794033 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:58.446937084 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.447051048 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.447068930 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:58.900587082 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:58.900679111 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.901236057 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.901254892 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:58.902009964 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:58.902367115 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:58.948276043 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.018646002 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:57:59.206824064 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.206871033 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.206914902 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.206935883 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.206979036 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207010031 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.207050085 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.207056046 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207083941 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207117081 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207117081 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.207148075 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.207163095 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207211971 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.207226038 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207279921 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.207324028 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.208969116 CET49737443192.168.2.423.103.209.28
                    Mar 26, 2025 01:57:59.208993912 CET4434973723.103.209.28192.168.2.4
                    Mar 26, 2025 01:57:59.925076962 CET49671443192.168.2.4204.79.197.203
                    Mar 26, 2025 01:57:59.993982077 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:59.994038105 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:57:59.994203091 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:01.849370956 CET49723443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:01.849400997 CET44349723142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:08.618676901 CET49678443192.168.2.420.189.173.27
                    Mar 26, 2025 01:58:49.759231091 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:49.759336948 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:49.759463072 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:49.759614944 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:49.759638071 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:49.949270964 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:49.949539900 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:58:49.949590921 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:59.949956894 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:59.950015068 CET44349743142.251.40.196192.168.2.4
                    Mar 26, 2025 01:58:59.950203896 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:59:01.848155022 CET49743443192.168.2.4142.251.40.196
                    Mar 26, 2025 01:59:01.848217010 CET44349743142.251.40.196192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Mar 26, 2025 01:57:45.886795998 CET53542691.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:45.902930021 CET53568071.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:46.491627932 CET53577561.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:46.575021982 CET53529221.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:49.706882000 CET5391953192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:49.707182884 CET6078453192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:49.804002047 CET53607841.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:49.805320978 CET53539191.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:51.663768053 CET5888653192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:51.663862944 CET6115253192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:51.815254927 CET53611521.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:51.816668034 CET53588861.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:58.241349936 CET6030953192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:58.241584063 CET4973453192.168.2.41.1.1.1
                    Mar 26, 2025 01:57:58.412461996 CET53603091.1.1.1192.168.2.4
                    Mar 26, 2025 01:57:58.446156025 CET53497341.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:03.481544971 CET53528531.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:22.340908051 CET53495941.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:44.790582895 CET53514111.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:45.379599094 CET53553051.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:48.117305994 CET53617771.1.1.1192.168.2.4
                    Mar 26, 2025 01:58:49.103167057 CET138138192.168.2.4192.168.2.255
                    TimestampSource IPDest IPChecksumCodeType
                    Mar 26, 2025 01:57:46.487552881 CET192.168.2.41.1.1.1c1f9(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Mar 26, 2025 01:57:49.706882000 CET192.168.2.41.1.1.10x1117Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:49.707182884 CET192.168.2.41.1.1.10xb89dStandard query (0)www.google.com65IN (0x0001)false
                    Mar 26, 2025 01:57:51.663768053 CET192.168.2.41.1.1.10xc8eeStandard query (0)usg02.safelinks.protection.office365.usA (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:51.663862944 CET192.168.2.41.1.1.10xa534Standard query (0)usg02.safelinks.protection.office365.us65IN (0x0001)false
                    Mar 26, 2025 01:57:58.241349936 CET192.168.2.41.1.1.10xa387Standard query (0)usg02.safelinks.protection.office365.usA (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:58.241584063 CET192.168.2.41.1.1.10xefe2Standard query (0)usg02.safelinks.protection.office365.us65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Mar 26, 2025 01:57:49.804002047 CET1.1.1.1192.168.2.40xb89dNo error (0)www.google.com65IN (0x0001)false
                    Mar 26, 2025 01:57:49.805320978 CET1.1.1.1192.168.2.40x1117No error (0)www.google.com142.251.40.196A (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:51.816668034 CET1.1.1.1192.168.2.40xc8eeNo error (0)usg02.safelinks.protection.office365.us23.103.208.28A (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:51.816668034 CET1.1.1.1192.168.2.40xc8eeNo error (0)usg02.safelinks.protection.office365.us23.103.209.28A (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:58.412461996 CET1.1.1.1192.168.2.40xa387No error (0)usg02.safelinks.protection.office365.us23.103.209.28A (IP address)IN (0x0001)false
                    Mar 26, 2025 01:57:58.412461996 CET1.1.1.1192.168.2.40xa387No error (0)usg02.safelinks.protection.office365.us23.103.208.28A (IP address)IN (0x0001)false
                    • usg02.safelinks.protection.office365.us
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44972723.103.208.284434320C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-03-26 00:57:52 UTC1754OUTGET /?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIu [TRUNCATED]
                    Host: usg02.safelinks.protection.office365.us
                    Connection: keep-alive
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-03-26 00:57:57 UTC612INHTTP/1.1 200 OK
                    Cache-Control: private
                    Content-Type: text/html; charset=utf-8
                    Server: Microsoft-IIS/10.0
                    X-AspNetMvc-Version: 5.2
                    X-SL-GetUrlReputation-Verdict: Bad
                    X-Robots-Tag: noindex, nofollow
                    X-AspNet-Version: 4.0.30319
                    X-ServerName: BN3USG02WS016
                    X-ServerVersion: 15.20.8583.026
                    X-ServerLat: 5050
                    X-SafeLinks-Tracking-Id: 64b03e3c-97da-4a7d-381f-08dd6c013c7e
                    X-Powered-By: ASP.NET
                    X-Content-Type-Options: nosniff
                    X-UA-Compatible: IE=Edge
                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                    Date: Wed, 26 Mar 2025 00:57:56 GMT
                    Connection: close
                    Content-Length: 6481
                    2025-03-26 00:57:57 UTC6481INData Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 4d 69 63 72 6f 73 6f 66 74 20 44 65 66 65 6e 64 65 72 20 66 6f 72 20 4f 66 66 69 63 65 20 33 36 35 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 65 66 65 72 72 65 72 22 20 63 6f 6e 74 65 6e 74 3d 22 73 61 6d 65 2d 6f 72 69 67 69 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 22 20 2f 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 64 61 74 61 3a 2c
                    Data Ascii: <!doctype html><html><head> <meta charset="UTF-8"> <title>Microsoft Defender for Office 365</title> <meta name="referrer" content="same-origin" /> <meta name="robots" content="noindex,nofollow" /> <link rel="icon" href="data:,


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44972623.103.208.284434320C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-03-26 00:57:57 UTC1680OUTGET /Content/Scripts/safelinksv2.css HTTP/1.1
                    Host: usg02.safelinks.protection.office365.us
                    Connection: keep-alive
                    sec-ch-ua-platform: "Windows"
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    Accept: text/css,*/*;q=0.1
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: style
                    Referer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpb [TRUNCATED]
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-03-26 00:57:57 UTC539INHTTP/1.1 200 OK
                    Content-Type: text/css
                    Last-Modified: Tue, 25 Mar 2025 09:25:08 GMT
                    Accept-Ranges: bytes
                    ETag: "0b2c1cc679ddb1:0"
                    Server: Microsoft-IIS/10.0
                    X-ServerName: BN3USG02WS013
                    X-ServerVersion: 15.20.8583.026
                    X-ServerLat: 3
                    X-SafeLinks-Tracking-Id: 93288cbe-bcbe-4d48-de61-08dd6c013f95
                    X-Powered-By: ASP.NET
                    X-Content-Type-Options: nosniff
                    X-UA-Compatible: IE=Edge
                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                    Date: Wed, 26 Mar 2025 00:57:56 GMT
                    Connection: close
                    Content-Length: 3932
                    2025-03-26 00:57:57 UTC3932INData Raw: 40 63 68 61 72 73 65 74 20 22 55 54 46 2d 38 22 3b 0d 0a 2f 2a 20 43 53 53 20 44 6f 63 75 6d 65 6e 74 20 2a 2f 0d 0a 0d 0a 62 6f 64 79 7b 0d 0a 09 6d 61 72 67 69 6e 3a 30 70 78 3b 0d 0a 09 70 61 64 64 69 6e 67 3a 30 70 78 3b 0d 0a 7d 0d 0a 0d 0a 64 69 76 7b 0d 0a 20 20 20 20 74 65 78 74 2d 61 6c 69 67 6e 3a 6c 65 66 74 3b 0d 0a 7d 0d 0a 0d 0a 23 72 65 63 6f 6d 6d 65 6e 64 61 74 69 6f 6e 5f 63 6f 6e 74 61 69 6e 65 72 7b 0d 0a 09 77 69 64 74 68 3a 31 30 30 25 3b 0d 0a 7d 0d 0a 0d 0a 23 69 63 6f 6e 20 69 6d 67 20 7b 0d 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 34 30 70 78 3b 0d 0a 09 6d 61 72 67 69 6e 2d 74 6f 70 3a 20 34 35 70 78 3b 0d 0a 7d 0d 0a 0d 0a 23 75 72 6c 20 7b 68 65 69 67 68 74 3a 20 33 32 70 78 3b 0d 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f
                    Data Ascii: @charset "UTF-8";/* CSS Document */body{margin:0px;padding:0px;}div{ text-align:left;}#recommendation_container{width:100%;}#icon img {margin-left: 40px;margin-top: 45px;}#url {height: 32px;background-co


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44973223.103.208.284434320C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-03-26 00:57:57 UTC1658OUTGET /Content/Scripts/site.js HTTP/1.1
                    Host: usg02.safelinks.protection.office365.us
                    Connection: keep-alive
                    sec-ch-ua-platform: "Windows"
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    Accept: */*
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: script
                    Referer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpb [TRUNCATED]
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-03-26 00:57:57 UTC553INHTTP/1.1 200 OK
                    Content-Type: application/javascript
                    Last-Modified: Tue, 25 Mar 2025 09:25:08 GMT
                    Accept-Ranges: bytes
                    ETag: "0b2c1cc679ddb1:0"
                    Server: Microsoft-IIS/10.0
                    X-ServerName: BN3USG02WS012
                    X-ServerVersion: 15.20.8583.026
                    X-ServerLat: 3
                    X-SafeLinks-Tracking-Id: 7eb64138-d712-4c5a-65dd-08dd6c013fc7
                    X-Powered-By: ASP.NET
                    X-Content-Type-Options: nosniff
                    X-UA-Compatible: IE=Edge
                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                    Date: Wed, 26 Mar 2025 00:57:56 GMT
                    Connection: close
                    Content-Length: 1588
                    2025-03-26 00:57:57 UTC1588INData Raw: 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 4f 6e 4c 6f 61 64 48 61 6e 64 6c 65 72 28 29 7b 0d 0a 09 69 66 20 28 77 69 6e 64 6f 77 2e 68 69 73 74 6f 72 79 2e 6c 65 6e 67 74 68 20 3c 3d 20 31 29 20 7b 0d 0a 09 09 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 63 6c 6f 73 65 22 29 2e 73 74 79 6c 65 2e 64 69 73 70 6c 61 79 20 3d 20 22 6e 6f 6e 65 22 3b 0d 0a 09 7d 0d 0a 7d 0d 0a 0d 0a 76 61 72 20 74 68 65 6d 65 20 3d 20 6e 75 6c 6c 3b 0d 0a 74 72 79 20 7b 0d 0a 20 20 28 66 75 6e 63 74 69 6f 6e 20 28 55 52 4c 53 65 61 72 63 68 50 61 72 61 6d 73 2c 20 73 74 72 29 20 7b 0d 0a 20 20 20 20 69 66 20 28 21 6e 65 77 20 55 52 4c 53 65 61 72 63 68 50 61 72 61 6d 73 28 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f
                    Data Ascii: window.onload = function OnLoadHandler(){if (window.history.length <= 1) {document.getElementById("close").style.display = "none";}}var theme = null;try { (function (URLSearchParams, str) { if (!new URLSearchParams(window.locatio


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.44973523.103.208.284434320C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-03-26 00:57:57 UTC1719OUTGET /Content/images/cross.png HTTP/1.1
                    Host: usg02.safelinks.protection.office365.us
                    Connection: keep-alive
                    sec-ch-ua-platform: "Windows"
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpb [TRUNCATED]
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-03-26 00:57:58 UTC540INHTTP/1.1 200 OK
                    Content-Type: image/png
                    Last-Modified: Mon, 24 Mar 2025 10:23:54 GMT
                    Accept-Ranges: bytes
                    ETag: "0d90d8a69cdb1:0"
                    Server: Microsoft-IIS/10.0
                    X-ServerName: BN3USG02WS008
                    X-ServerVersion: 15.20.8583.023
                    X-ServerLat: 3
                    X-SafeLinks-Tracking-Id: 1c76aefa-1452-4780-25d7-08dd6c013fec
                    X-Powered-By: ASP.NET
                    X-Content-Type-Options: nosniff
                    X-UA-Compatible: IE=Edge
                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                    Date: Wed, 26 Mar 2025 00:57:57 GMT
                    Connection: close
                    Content-Length: 25664
                    2025-03-26 00:57:58 UTC15844INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 ba 00 00 00 c8 08 06 00 00 00 5f e4 fb 3b 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 0a 4f 69 43 43 50 50 68 6f 74 6f 73 68 6f 70 20 49 43 43 20 70 72 6f 66 69 6c 65 00 00 78 da 9d 53 67 54 53 e9 16 3d f7 de f4 42 4b 88 80 94 4b 6f 52 15 08 20 52 42 8b 80 14 91 26 2a 21 09 10 4a 88 21 a1 d9 15 51 c1 11 45 45 04 1b c8 a0 88 03 8e 8e 80 8c 15 51 2c 0c 8a 0a d8 07 e4 21 a2 8e 83 a3 88 8a ca fb e1 7b a3 6b d6 bc f7 e6 cd fe b5 d7 3e e7 ac f3 9d b3 cf 07 c0 08 0c 96 48 33 51 35 80 0c a9 42 1e 11 e0 83 c7 c4 c6 e1 e4 2e 40 81 0a 24 70 00 10 08 b3 64 21 73 fd 23 01 00 f8 7e 3c 3c 2b 22 c0 07 be 00 01 78 d3 0b 08 00 c0 4d 9b c0 30 1c 87 ff 0f ea 42 99 5c 01 80 84 01 c0 74 91 38 4b
                    Data Ascii: PNGIHDR_;pHYs%%IR$OiCCPPhotoshop ICC profilexSgTS=BKKoR RB&*!J!QEEQ,!{k>H3Q5B.@$pd!s#~<<+"xM0B\t8K
                    2025-03-26 00:57:58 UTC9820INData Raw: 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.44973723.103.209.284434320C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-03-26 00:57:58 UTC427OUTGET /Content/images/cross.png HTTP/1.1
                    Host: usg02.safelinks.protection.office365.us
                    Connection: keep-alive
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: */*
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: cors
                    Sec-Fetch-Dest: empty
                    Sec-Fetch-Storage-Access: active
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-03-26 00:57:59 UTC541INHTTP/1.1 200 OK
                    Content-Type: image/png
                    Last-Modified: Sun, 23 Mar 2025 09:13:08 GMT
                    Accept-Ranges: bytes
                    ETag: "0eac6cad39bdb1:0"
                    Server: Microsoft-IIS/10.0
                    X-ServerName: CY1USG02WS014
                    X-ServerVersion: 15.20.8583.023
                    X-ServerLat: 1
                    X-SafeLinks-Tracking-Id: 4ecac410-1c0b-4c82-d8fe-08dd6c014085
                    X-Powered-By: ASP.NET
                    X-Content-Type-Options: nosniff
                    X-UA-Compatible: IE=Edge
                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                    Date: Wed, 26 Mar 2025 00:57:58 GMT
                    Connection: close
                    Content-Length: 25664
                    2025-03-26 00:57:59 UTC15843INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 ba 00 00 00 c8 08 06 00 00 00 5f e4 fb 3b 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 0a 4f 69 43 43 50 50 68 6f 74 6f 73 68 6f 70 20 49 43 43 20 70 72 6f 66 69 6c 65 00 00 78 da 9d 53 67 54 53 e9 16 3d f7 de f4 42 4b 88 80 94 4b 6f 52 15 08 20 52 42 8b 80 14 91 26 2a 21 09 10 4a 88 21 a1 d9 15 51 c1 11 45 45 04 1b c8 a0 88 03 8e 8e 80 8c 15 51 2c 0c 8a 0a d8 07 e4 21 a2 8e 83 a3 88 8a ca fb e1 7b a3 6b d6 bc f7 e6 cd fe b5 d7 3e e7 ac f3 9d b3 cf 07 c0 08 0c 96 48 33 51 35 80 0c a9 42 1e 11 e0 83 c7 c4 c6 e1 e4 2e 40 81 0a 24 70 00 10 08 b3 64 21 73 fd 23 01 00 f8 7e 3c 3c 2b 22 c0 07 be 00 01 78 d3 0b 08 00 c0 4d 9b c0 30 1c 87 ff 0f ea 42 99 5c 01 80 84 01 c0 74 91 38 4b
                    Data Ascii: PNGIHDR_;pHYs%%IR$OiCCPPhotoshop ICC profilexSgTS=BKKoR RB&*!J!QEEQ,!{k>H3Q5B.@$pd!s#~<<+"xM0B\t8K
                    2025-03-26 00:57:59 UTC9821INData Raw: 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                    Data Ascii:


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0050100MB

                    Click to jump to process

                    Target ID:1
                    Start time:20:57:40
                    Start date:25/03/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff786830000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:20:57:43
                    Start date:25/03/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2292,i,17352436165678199142,10092777188710425798,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2492 /prefetch:3
                    Imagebase:0x7ff786830000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:9
                    Start time:20:57:50
                    Start date:25/03/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0"
                    Imagebase:0x7ff786830000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly