Edit tour

Windows Analysis Report
https://auth.berger-levrault.com

Overview

General Information

Sample URL:https://auth.berger-levrault.com
Analysis ID:1658349
Infos:

Detection

Score:2
Range:0 - 100
Confidence:100%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder
HTML body with high number of embedded images detected
HTML page contains hidden javascript code

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 800 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1800,i,5765859814087684943,14114047180601535032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2040 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6028 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://auth.berger-levrault.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://auth.berger-levrault.com/HTTP Parser: Total embedded image size: 14548
Source: https://auth.berger-levrault.com/HTTP Parser: Base64 decoded: body, html { height: 100%; margin: 0; display: flex; justify-content: center; align-items: center; background-color: #ffffff; } .conteneur { ...
Source: https://auth.berger-levrault.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.251.41.4:443 -> 192.168.2.7:49688 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.19.141.174:443 -> 192.168.2.7:49689 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.19.141.174:443 -> 192.168.2.7:49690 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.215.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.98.62
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.215.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.98.62
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.15
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: auth.berger-levrault.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIk6HLAQiKo8sBCIWgzQEI9s/OAQjI0c4BCIDWzgEIydzOAQiE4M4BCKLkzgEIr+TOAQjp5M4BSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: auth.berger-levrault.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://auth.berger-levrault.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: auth.berger-levrault.com
Source: global trafficDNS traffic detected: DNS query: beacons.gcp.gvt2.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownHTTPS traffic detected: 142.251.41.4:443 -> 192.168.2.7:49688 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.19.141.174:443 -> 192.168.2.7:49689 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.19.141.174:443 -> 192.168.2.7:49690 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3584_650674951Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3584_650674951Jump to behavior
Source: classification engineClassification label: clean2.win@21/6@13/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1800,i,5765859814087684943,14114047180601535032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2040 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://auth.berger-levrault.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1800,i,5765859814087684943,14114047180601535032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2040 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1658349 URL: https://auth.berger-levrault.com Startdate: 07/04/2025 Architecture: WINDOWS Score: 2 14 beacons.gcp.gvt2.com 2->14 16 beacons-handoff.gcp.gvt2.com 2->16 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 18 192.168.2.7, 443, 49261, 49509 unknown unknown 6->18 11 chrome.exe 6->11         started        process5 dnsIp6 20 auth.berger-levrault.com 20.19.141.174, 443, 49689, 49690 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 11->20 22 www.google.com 142.251.41.4, 443, 49688, 49709 GOOGLEUS United States 11->22 24 2 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://auth.berger-levrault.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://auth.berger-levrault.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
beacons-handoff.gcp.gvt2.com
142.251.116.94
truefalse
    high
    www.google.com
    142.251.41.4
    truefalse
      high
      auth.berger-levrault.com
      20.19.141.174
      truefalse
        unknown
        beacons.gcp.gvt2.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          http://c.pki.goog/r/gsr1.crlfalse
            high
            http://c.pki.goog/r/r4.crlfalse
              high
              https://auth.berger-levrault.com/false
                unknown
                https://auth.berger-levrault.com/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  20.19.141.174
                  auth.berger-levrault.comUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  142.251.41.4
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.7
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1658349
                  Start date and time:2025-04-07 15:30:25 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 2m 52s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://auth.berger-levrault.com
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:14
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean2.win@21/6@13/3
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe, TextInputHost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.80.14, 142.250.80.99, 142.250.80.110, 142.251.167.84, 142.251.41.14, 142.250.65.174, 142.251.32.110, 142.251.40.170, 199.232.210.172, 142.250.81.238, 172.217.165.142, 142.250.65.206, 142.250.65.195, 142.251.40.195, 142.250.64.110, 4.245.163.56, 184.31.69.3
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, translate.googleapis.com, update.googleapis.com, clients.l.google.com, c.pki.goog
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • VT rate limit hit for: https://auth.berger-levrault.com
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, Unicode text, UTF-8 text, with very long lines (7405)
                  Category:downloaded
                  Size (bytes):20837
                  Entropy (8bit):5.9967108964092315
                  Encrypted:false
                  SSDEEP:384:50tDCiUXd6tTImk936tTImk9W6tTImk9T3WSxCdnVsAM/0mcEQD+PURSpD:mtDLUXgtpRtpYtpg2dnV3M/3Jj8wF
                  MD5:EA13FE5F9275189529ED55334BFBD2AE
                  SHA1:40677BC945F215ED8B5ADC71F1F1D0E22DB445A8
                  SHA-256:554FB1F3C5B33A80C20E452B1D54D7DCF6F763E4355A49F80B652984AFEDE27C
                  SHA-512:ED27ED319D1C6F9D2E63C0A8DB0D25C609DEBB2FB14E8414482BAAEA10853588CD1C32EDB7D4A7A02514C70CB8EBC6EC906B6CC011FA1D5369CE586DD2A73909
                  Malicious:false
                  Reputation:low
                  URL:https://auth.berger-levrault.com/favicon.ico
                  Preview:<!DOCTYPE html>.<html lang="fr">.<head>. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>BL.Security - Service Unavailable</title>. <style type="text/css">. @import url("data:text/css;base64,ICAgICAgICBib2R5LCBodG1sIHsNCiAgICAgICAgICAgIGhlaWdodDogMTAwJTsNCiAgICAgICAgICAgIG1hcmdpbjogMDsNCiAgICAgICAgICAgIGRpc3BsYXk6IGZsZXg7DQogICAgICAgICAgICBqdXN0aWZ5LWNvbnRlbnQ6IGNlbnRlcjsNCiAgICAgICAgICAgIGFsaWduLWl0ZW1zOiBjZW50ZXI7DQogICAgICAgICAgICBiYWNrZ3JvdW5kLWNvbG9yOiAjZmZmZmZmOw0KICAgICAgICB9DQoNCiAgICAgICAgLmNvbnRlbmV1ciB7DQogICAgICAgICAgICBwb3NpdGlvbjogcmVsYXRpdmU7DQogICAgICAgICAgICB3aWR0aDogOTU3cHg7DQogICAgICAgICAgICBoZWlnaHQ6IDMyOHB4Ow0KICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogIzU2NGRhNjsNCiAgICAgICAgICAgIG92ZXJmbG93OiBoaWRkZW47DQogICAgICAgICAgICBkaXNwbGF5OiBmbGV4Ow0KICAgICAgICAgICAganVzdGlmeS1jb250ZW50OiBzcGFjZS1iZXR3ZWVuOw0KICAgICAgICAgICAgYWxpZ24taXRlbXM6IGZsZXgtZW5kOw0KICAgICAgICB9DQoNCiAgICAgICAgLnJlY3RhbmdsZS1kcm9pdGUge
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (5456)
                  Category:downloaded
                  Size (bytes):5461
                  Entropy (8bit):5.818900576177257
                  Encrypted:false
                  SSDEEP:96:UFnlSFd66666m5mfjxTi/431Zaa0G6twMg+DlGpYN7ZrL33Kn/wlXegNy2ffffQo:6SFd66666rfjxTJ1Za4qfk6N7BW/wleI
                  MD5:DC320FA908F0B93045DE520266052760
                  SHA1:F3884CAB2803F3323EC7E84178661ABA76420050
                  SHA-256:6030046212BA1EF615AB4F331704267AB411B437925DD867E40BE027AC66CBA5
                  SHA-512:422D63D1AC8587ED7C11A554BEC372E86CE34F37D5F92032B8FAC8057BC73BDEC19DF21405F0566BC4D92A3FD7D018E7859B5037291D4CBE539135EA083DFC61
                  Malicious:false
                  Reputation:low
                  URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
                  Preview:)]}'.["",["the pitt season 2","florida softball coach ejected","skier dies sugarloaf mountain","boycotting walmart","snow white disney movie box office","ncaa college basketball","minke whale long beach harbor","kentucky flooding buffalo trace"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"google:entityinfo":"CgkvbS8wMzl5enMSK0NvbGxlZ2UgYmFza2V0YmFsbCDigJQgQXRobGV0aWMgYXNzb2NpYXRpb24ysxlkYXRhOmltYWdlL2pwZWc7YmFzZTY0LC85ai80QUFRU2taSlJnQUJBUUFBQVFBQkFBRC8yd0NFQUFrR0J3Z0hCZ2tJQndnS0Nna0xEUllQRFF3TURSc1VGUkFXSUIwaUlpQWRIeDhrS0RRc0pDWXhKeDhmTFQwdE1UVTNPam82SXlzL1JEODRRelE1T2pjQkNnb0tEUXdOR2c4UEdqY2xIeVUzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM04vL0FBQkVJQUVBQVFBTUJFUUFDRVFFREVRSC94QUFjQUFBQ0FnTUJBUUFBQUFBQUFBQUFBQUFFQmdVSEFBSURDQUgveEFBekVBQUJBd0lGQWdVRE
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, Unicode text, UTF-8 text, with very long lines (7405)
                  Category:downloaded
                  Size (bytes):20837
                  Entropy (8bit):5.9967108964092315
                  Encrypted:false
                  SSDEEP:384:50tDCiUXd6tTImk936tTImk9W6tTImk9T3WSxCdnVsAM/0mcEQD+PURSpD:mtDLUXgtpRtpYtpg2dnV3M/3Jj8wF
                  MD5:EA13FE5F9275189529ED55334BFBD2AE
                  SHA1:40677BC945F215ED8B5ADC71F1F1D0E22DB445A8
                  SHA-256:554FB1F3C5B33A80C20E452B1D54D7DCF6F763E4355A49F80B652984AFEDE27C
                  SHA-512:ED27ED319D1C6F9D2E63C0A8DB0D25C609DEBB2FB14E8414482BAAEA10853588CD1C32EDB7D4A7A02514C70CB8EBC6EC906B6CC011FA1D5369CE586DD2A73909
                  Malicious:false
                  Reputation:low
                  URL:https://auth.berger-levrault.com/
                  Preview:<!DOCTYPE html>.<html lang="fr">.<head>. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>BL.Security - Service Unavailable</title>. <style type="text/css">. @import url("data:text/css;base64,ICAgICAgICBib2R5LCBodG1sIHsNCiAgICAgICAgICAgIGhlaWdodDogMTAwJTsNCiAgICAgICAgICAgIG1hcmdpbjogMDsNCiAgICAgICAgICAgIGRpc3BsYXk6IGZsZXg7DQogICAgICAgICAgICBqdXN0aWZ5LWNvbnRlbnQ6IGNlbnRlcjsNCiAgICAgICAgICAgIGFsaWduLWl0ZW1zOiBjZW50ZXI7DQogICAgICAgICAgICBiYWNrZ3JvdW5kLWNvbG9yOiAjZmZmZmZmOw0KICAgICAgICB9DQoNCiAgICAgICAgLmNvbnRlbmV1ciB7DQogICAgICAgICAgICBwb3NpdGlvbjogcmVsYXRpdmU7DQogICAgICAgICAgICB3aWR0aDogOTU3cHg7DQogICAgICAgICAgICBoZWlnaHQ6IDMyOHB4Ow0KICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogIzU2NGRhNjsNCiAgICAgICAgICAgIG92ZXJmbG93OiBoaWRkZW47DQogICAgICAgICAgICBkaXNwbGF5OiBmbGV4Ow0KICAgICAgICAgICAganVzdGlmeS1jb250ZW50OiBzcGFjZS1iZXR3ZWVuOw0KICAgICAgICAgICAgYWxpZ24taXRlbXM6IGZsZXgtZW5kOw0KICAgICAgICB9DQoNCiAgICAgICAgLnJlY3RhbmdsZS1kcm9pdGUge
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 87
                  • 443 (HTTPS)
                  • 80 (HTTP)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 7, 2025 15:31:12.459638119 CEST4967680192.168.2.723.199.215.203
                  Apr 7, 2025 15:31:12.459640026 CEST49677443192.168.2.72.18.98.62
                  Apr 7, 2025 15:31:13.022108078 CEST49675443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:13.022109032 CEST49673443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:13.022125006 CEST49674443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:19.638425112 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:19.638465881 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:19.638698101 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:19.639591932 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:19.639621019 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:19.845807076 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:19.845982075 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:19.847687006 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:19.847695112 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:19.847939014 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:19.897479057 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.031939030 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.031980991 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.032051086 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.033060074 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.033163071 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.033235073 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.033817053 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.033827066 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.033854961 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.033904076 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.399663925 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.399833918 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.401143074 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.401155949 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.401393890 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.401782990 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.407994032 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.408124924 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.409229994 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.409257889 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.409624100 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.444279909 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.462794065 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.778145075 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.778175116 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.778188944 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.778312922 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.778328896 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.778388977 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.824907064 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.872262955 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.908724070 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.908850908 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.908947945 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.909737110 CEST49689443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:21.909760952 CEST4434968920.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:21.951771975 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.951822996 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.951852083 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.951873064 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.951894045 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.951946020 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.957993984 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.962086916 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.962157011 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.962172985 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.962217093 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:21.962266922 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.968174934 CEST49688443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:31:21.968184948 CEST44349688142.251.41.4192.168.2.7
                  Apr 7, 2025 15:31:22.015367985 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.056294918 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.068034887 CEST4967680192.168.2.723.199.215.203
                  Apr 7, 2025 15:31:22.068223953 CEST49677443192.168.2.72.18.98.62
                  Apr 7, 2025 15:31:22.358377934 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358418941 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358427048 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358448982 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358459949 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358474970 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358490944 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.358553886 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358598948 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.358634949 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.358745098 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358803988 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.358819008 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358843088 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.358872890 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.358903885 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.368180037 CEST49690443192.168.2.720.19.141.174
                  Apr 7, 2025 15:31:22.368220091 CEST4434969020.19.141.174192.168.2.7
                  Apr 7, 2025 15:31:22.633498907 CEST49674443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:22.633497953 CEST49675443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:22.633502960 CEST49673443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:32.609967947 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:31:32.704022884 CEST8049697142.251.41.3192.168.2.7
                  Apr 7, 2025 15:31:32.704248905 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:31:32.704395056 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:31:32.797425985 CEST8049697142.251.41.3192.168.2.7
                  Apr 7, 2025 15:31:32.797657967 CEST8049697142.251.41.3192.168.2.7
                  Apr 7, 2025 15:31:32.803603888 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:31:32.897146940 CEST8049697142.251.41.3192.168.2.7
                  Apr 7, 2025 15:31:32.945041895 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:31:33.940270901 CEST49672443192.168.2.72.23.227.208
                  Apr 7, 2025 15:31:33.940315008 CEST443496722.23.227.208192.168.2.7
                  Apr 7, 2025 15:31:49.305813074 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:49.605731010 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:50.211713076 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:51.414284945 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:53.821100950 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:57.870023012 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:31:58.171648979 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:31:58.628794909 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:31:58.775609970 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:31:59.975480080 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:32:02.379602909 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:32:07.184804916 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:32:08.232309103 CEST49671443192.168.2.7204.79.197.203
                  Apr 7, 2025 15:32:16.788074017 CEST49678443192.168.2.720.189.173.15
                  Apr 7, 2025 15:32:19.603739023 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:19.603776932 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:19.603876114 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:19.604129076 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:19.604160070 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:19.805270910 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:19.806237936 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:19.806303978 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:29.804874897 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:29.804964066 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:29.805289030 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:29.975775003 CEST49709443192.168.2.7142.251.41.4
                  Apr 7, 2025 15:32:29.975848913 CEST44349709142.251.41.4192.168.2.7
                  Apr 7, 2025 15:32:33.103318930 CEST4969780192.168.2.7142.251.41.3
                  Apr 7, 2025 15:32:33.196501017 CEST8049697142.251.41.3192.168.2.7
                  Apr 7, 2025 15:32:33.196577072 CEST4969780192.168.2.7142.251.41.3
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 7, 2025 15:31:15.076999903 CEST53528701.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:15.131789923 CEST53570971.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:16.013914108 CEST53507831.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:19.539180994 CEST4950953192.168.2.71.1.1.1
                  Apr 7, 2025 15:31:19.539499044 CEST5575153192.168.2.71.1.1.1
                  Apr 7, 2025 15:31:19.635940075 CEST53495091.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:19.636502028 CEST53557511.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:20.783298969 CEST5399753192.168.2.71.1.1.1
                  Apr 7, 2025 15:31:20.784122944 CEST5038353192.168.2.71.1.1.1
                  Apr 7, 2025 15:31:20.995423079 CEST53539971.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:21.024983883 CEST53503831.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:22.031480074 CEST53600641.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:33.122159004 CEST53609631.1.1.1192.168.2.7
                  Apr 7, 2025 15:31:52.204945087 CEST53543991.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:14.925602913 CEST53549131.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:15.061939001 CEST53567421.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:17.983021975 CEST53638721.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:21.974984884 CEST5433153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:21.975249052 CEST5635453192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:22.075149059 CEST53563541.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:22.075268030 CEST53543311.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:22.993288040 CEST5914753192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:22.993429899 CEST5579253192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:23.090862036 CEST53591471.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:23.091281891 CEST53557921.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:25.027672052 CEST4926153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:25.132935047 CEST53492611.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:26.048728943 CEST4926153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:26.145697117 CEST53492611.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:27.055247068 CEST4926153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:27.152579069 CEST53492611.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:29.081855059 CEST4926153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:29.181507111 CEST53492611.1.1.1192.168.2.7
                  Apr 7, 2025 15:32:33.088386059 CEST4926153192.168.2.71.1.1.1
                  Apr 7, 2025 15:32:33.188227892 CEST53492611.1.1.1192.168.2.7
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Apr 7, 2025 15:31:19.539180994 CEST192.168.2.71.1.1.10x61afStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:31:19.539499044 CEST192.168.2.71.1.1.10xda82Standard query (0)www.google.com65IN (0x0001)false
                  Apr 7, 2025 15:31:20.783298969 CEST192.168.2.71.1.1.10x4a34Standard query (0)auth.berger-levrault.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:31:20.784122944 CEST192.168.2.71.1.1.10x207bStandard query (0)auth.berger-levrault.com65IN (0x0001)false
                  Apr 7, 2025 15:32:21.974984884 CEST192.168.2.71.1.1.10xe88fStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:21.975249052 CEST192.168.2.71.1.1.10xd85bStandard query (0)beacons.gcp.gvt2.com65IN (0x0001)false
                  Apr 7, 2025 15:32:22.993288040 CEST192.168.2.71.1.1.10xb345Standard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:22.993429899 CEST192.168.2.71.1.1.10x7a2aStandard query (0)beacons.gcp.gvt2.com65IN (0x0001)false
                  Apr 7, 2025 15:32:25.027672052 CEST192.168.2.71.1.1.10x184dStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:26.048728943 CEST192.168.2.71.1.1.10x184dStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:27.055247068 CEST192.168.2.71.1.1.10x184dStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:29.081855059 CEST192.168.2.71.1.1.10x184dStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:33.088386059 CEST192.168.2.71.1.1.10x184dStandard query (0)beacons.gcp.gvt2.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Apr 7, 2025 15:31:19.635940075 CEST1.1.1.1192.168.2.70x61afNo error (0)www.google.com142.251.41.4A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:31:19.636502028 CEST1.1.1.1192.168.2.70xda82No error (0)www.google.com65IN (0x0001)false
                  Apr 7, 2025 15:31:20.995423079 CEST1.1.1.1192.168.2.70x4a34No error (0)auth.berger-levrault.com20.19.141.174A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:22.075149059 CEST1.1.1.1192.168.2.70xd85bNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:22.075268030 CEST1.1.1.1192.168.2.70xe88fNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:22.075268030 CEST1.1.1.1192.168.2.70xe88fNo error (0)beacons-handoff.gcp.gvt2.com142.251.116.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:23.090862036 CEST1.1.1.1192.168.2.70xb345No error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:23.090862036 CEST1.1.1.1192.168.2.70xb345No error (0)beacons-handoff.gcp.gvt2.com142.250.9.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:23.091281891 CEST1.1.1.1192.168.2.70x7a2aNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:25.132935047 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:25.132935047 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons-handoff.gcp.gvt2.com142.251.186.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:26.145697117 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:26.145697117 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons-handoff.gcp.gvt2.com142.251.186.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:27.152579069 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:27.152579069 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons-handoff.gcp.gvt2.com142.251.186.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:29.181507111 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:29.181507111 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons-handoff.gcp.gvt2.com142.251.186.94A (IP address)IN (0x0001)false
                  Apr 7, 2025 15:32:33.188227892 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons.gcp.gvt2.combeacons-handoff.gcp.gvt2.comCNAME (Canonical name)IN (0x0001)false
                  Apr 7, 2025 15:32:33.188227892 CEST1.1.1.1192.168.2.70x184dNo error (0)beacons-handoff.gcp.gvt2.com142.251.186.94A (IP address)IN (0x0001)false
                  • auth.berger-levrault.com
                  • www.google.com
                  • c.pki.goog
                  Session IDSource IPSource PortDestination IPDestination Port
                  0192.168.2.749697142.251.41.380
                  TimestampBytes transferredDirectionData
                  Apr 7, 2025 15:31:32.704395056 CEST202OUTGET /r/gsr1.crl HTTP/1.1
                  Cache-Control: max-age = 3000
                  Connection: Keep-Alive
                  Accept: */*
                  If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
                  User-Agent: Microsoft-CryptoAPI/10.0
                  Host: c.pki.goog
                  Apr 7, 2025 15:31:32.797657967 CEST223INHTTP/1.1 304 Not Modified
                  Date: Mon, 07 Apr 2025 13:13:36 GMT
                  Expires: Mon, 07 Apr 2025 14:03:36 GMT
                  Age: 1076
                  Last-Modified: Tue, 07 Jan 2025 07:28:00 GMT
                  Cache-Control: public, max-age=3000
                  Vary: Accept-Encoding
                  Apr 7, 2025 15:31:32.803603888 CEST200OUTGET /r/r4.crl HTTP/1.1
                  Cache-Control: max-age = 3000
                  Connection: Keep-Alive
                  Accept: */*
                  If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                  User-Agent: Microsoft-CryptoAPI/10.0
                  Host: c.pki.goog
                  Apr 7, 2025 15:31:32.897146940 CEST1242INHTTP/1.1 200 OK
                  Accept-Ranges: bytes
                  Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                  Cross-Origin-Resource-Policy: cross-origin
                  Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                  Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                  Content-Length: 530
                  X-Content-Type-Options: nosniff
                  Server: sffe
                  X-XSS-Protection: 0
                  Date: Mon, 07 Apr 2025 13:27:11 GMT
                  Expires: Mon, 07 Apr 2025 14:17:11 GMT
                  Cache-Control: public, max-age=3000
                  Age: 261
                  Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                  Content-Type: application/pkix-crl
                  Vary: Accept-Encoding
                  Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                  Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.74968920.19.141.174443800C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-07 13:31:21 UTC674OUTGET / HTTP/1.1
                  Host: auth.berger-levrault.com
                  Connection: keep-alive
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-07 13:31:21 UTC95INHTTP/1.1 503 Not Found
                  cache-control: no-cache
                  content-type: text/html
                  connection: close
                  2025-04-07 13:31:21 UTC16289INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 66 72 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 42 4c 2e 53 65 63 75 72 69 74 79 20 2d 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 40 69 6d 70 6f 72 74 20 75 72 6c 28 22 64 61 74 61 3a 74 65 78 74 2f 63 73 73 3b 62 61 73
                  Data Ascii: <!DOCTYPE html><html lang="fr"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>BL.Security - Service Unavailable</title> <style type="text/css"> @import url("data:text/css;bas
                  2025-04-07 13:31:21 UTC4548INData Raw: 51 73 61 6b 74 64 66 58 34 67 69 57 51 48 36 68 38 4b 44 36 48 4d 5a 62 55 4c 67 30 45 36 39 51 6a 4e 4e 44 6c 55 69 53 6b 6d 53 5a 47 73 56 53 37 7a 63 64 70 64 63 38 70 51 77 7a 6e 45 6b 62 6d 4d 46 67 75 4f 5a 4d 49 2b 42 79 6f 58 51 64 66 33 55 4e 6a 64 2b 73 78 66 42 34 71 48 78 6c 47 63 32 62 74 30 63 32 56 68 6b 6d 4b 45 58 69 53 65 4f 78 5a 36 65 44 4d 6e 73 30 4a 47 39 4a 4f 55 32 62 43 71 6a 37 62 43 57 31 48 36 2b 67 66 75 58 58 65 50 62 73 78 5a 36 56 53 65 49 70 4a 34 58 41 6b 78 4c 33 78 73 31 34 39 70 62 67 4b 64 35 4c 35 63 75 76 45 39 68 66 32 79 35 69 36 41 5a 61 6a 4a 50 6b 4d 79 59 69 48 66 62 2b 30 34 68 36 69 49 31 39 2f 53 69 67 51 68 71 34 77 37 51 73 67 46 52 54 39 69 64 46 71 39 35 6c 47 55 49 51 6b 7a 2b 45 41 53 63 65 6a 37 54
                  Data Ascii: QsaktdfX4giWQH6h8KD6HMZbULg0E69QjNNDlUiSkmSZGsVS7zcdpdc8pQwznEkbmMFguOZMI+ByoXQdf3UNjd+sxfB4qHxlGc2bt0c2VhkmKEXiSeOxZ6eDMns0JG9JOU2bCqj7bCW1H6+gfuXXePbsxZ6VSeIpJ4XAkxL3xs149pbgKd5L5cuvE9hf2y5i6AZajJPkMyYiHfb+04h6iI19/SigQhq4w7QsgFRT9idFq95lGUIQkz+EAScej7T


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.749688142.251.41.4443800C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-07 13:31:21 UTC579OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1
                  Host: www.google.com
                  Connection: keep-alive
                  X-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIk6HLAQiKo8sBCIWgzQEI9s/OAQjI0c4BCIDWzgEIydzOAQiE4M4BCKLkzgEIr+TOAQjp5M4B
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-07 13:31:21 UTC1303INHTTP/1.1 200 OK
                  Date: Mon, 07 Apr 2025 13:31:21 GMT
                  Pragma: no-cache
                  Expires: -1
                  Cache-Control: no-cache, must-revalidate
                  Content-Type: text/javascript; charset=UTF-8
                  Strict-Transport-Security: max-age=31536000
                  Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-9vIfB0_Hsch6H2ysoNxawg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                  Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                  Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                  Accept-CH: Sec-CH-Prefers-Color-Scheme
                  Accept-CH: Downlink
                  Accept-CH: RTT
                  Accept-CH: Sec-CH-UA-Form-Factors
                  Accept-CH: Sec-CH-UA-Platform
                  Accept-CH: Sec-CH-UA-Platform-Version
                  Accept-CH: Sec-CH-UA-Full-Version
                  Accept-CH: Sec-CH-UA-Arch
                  Accept-CH: Sec-CH-UA-Model
                  Accept-CH: Sec-CH-UA-Bitness
                  Accept-CH: Sec-CH-UA-Full-Version-List
                  Accept-CH: Sec-CH-UA-WoW64
                  Permissions-Policy: unload=()
                  Content-Disposition: attachment; filename="f.txt"
                  Server: gws
                  X-XSS-Protection: 0
                  X-Frame-Options: SAMEORIGIN
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2025-04-07 13:31:21 UTC1303INData Raw: 66 32 62 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 74 68 65 20 70 69 74 74 20 73 65 61 73 6f 6e 20 32 22 2c 22 66 6c 6f 72 69 64 61 20 73 6f 66 74 62 61 6c 6c 20 63 6f 61 63 68 20 65 6a 65 63 74 65 64 22 2c 22 73 6b 69 65 72 20 64 69 65 73 20 73 75 67 61 72 6c 6f 61 66 20 6d 6f 75 6e 74 61 69 6e 22 2c 22 62 6f 79 63 6f 74 74 69 6e 67 20 77 61 6c 6d 61 72 74 22 2c 22 73 6e 6f 77 20 77 68 69 74 65 20 64 69 73 6e 65 79 20 6d 6f 76 69 65 20 62 6f 78 20 6f 66 66 69 63 65 22 2c 22 6e 63 61 61 20 63 6f 6c 6c 65 67 65 20 62 61 73 6b 65 74 62 61 6c 6c 22 2c 22 6d 69 6e 6b 65 20 77 68 61 6c 65 20 6c 6f 6e 67 20 62 65 61 63 68 20 68 61 72 62 6f 72 22 2c 22 6b 65 6e 74 75 63 6b 79 20 66 6c 6f 6f 64 69 6e 67 20 62 75 66 66 61 6c 6f 20 74 72 61 63 65 22 5d 2c 5b 22 22 2c
                  Data Ascii: f2b)]}'["",["the pitt season 2","florida softball coach ejected","skier dies sugarloaf mountain","boycotting walmart","snow white disney movie box office","ncaa college basketball","minke whale long beach harbor","kentucky flooding buffalo trace"],["",
                  2025-04-07 13:31:21 UTC1303INData Raw: 4f 45 35 43 59 33 46 6a 5a 45 31 47 61 32 4e 31 64 57 46 75 56 55 51 31 53 6d 46 44 4f 55 6b 72 56 46 6c 5a 63 54 6c 55 61 6c 42 33 4f 43 38 7a 4e 58 6b 7a 4d 48 4a 71 4e 48 56 4b 63 46 56 6a 61 31 5a 78 52 6b 68 5a 62 45 35 4b 61 6c 52 76 61 6a 6c 31 62 6b 70 6f 55 45 4a 69 59 57 6c 6b 5a 30 78 74 4d 6a 56 50 64 7a 49 7a 54 33 63 7a 4d 6e 68 47 4d 55 4e 46 4d 54 4a 4e 61 6d 46 61 4d 54 56 49 54 56 68 75 56 7a 4e 48 57 46 5a 30 55 45 35 79 59 6d 4e 52 59 6b 74 52 64 45 70 54 63 45 6f 35 61 55 52 34 61 54 68 46 53 47 74 54 5a 32 64 6e 4d 46 70 77 61 56 52 72 65 6b 56 72 62 56 6c 72 61 32 78 68 51 6c 52 76 61 33 6c 54 57 47 46 30 54 6c 52 44 63 48 4a 4f 61 53 73 35 65 58 52 59 63 32 68 44 5a 56 4e 76 4c 31 52 5a 57 45 6f 72 59 54 68 71 62 46 4a 54 61 58 70
                  Data Ascii: OE5CY3FjZE1Ga2N1dWFuVUQ1SmFDOUkrVFlZcTlUalB3OC8zNXkzMHJqNHVKcFVja1ZxRkhZbE5KalRvajl1bkpoUEJiYWlkZ0xtMjVPdzIzT3czMnhGMUNFMTJNamFaMTVITVhuVzNHWFZ0UE5yYmNRYktRdEpTcEo5aUR4aThFSGtTZ2dnMFpwaVRrekVrbVlra2xhQlRva3lTWGF0TlRDcHJOaSs5eXRYc2hDZVNvL1RZWEorYThqbFJTaXp
                  2025-04-07 13:31:21 UTC1284INData Raw: 6c 56 30 64 4e 63 6a 42 79 65 54 5a 57 4f 57 46 58 4f 47 56 77 53 32 74 49 62 48 68 6d 4b 30 49 79 4b 7a 55 31 53 6e 68 55 62 58 6c 75 53 54 45 72 53 6d 52 70 65 47 70 48 53 32 74 54 61 46 70 75 5a 55 78 79 62 57 63 7a 59 6e 41 78 53 30 4e 47 4c 79 74 57 63 6c 5a 6c 4d 7a 4e 54 63 69 74 4e 56 32 52 30 55 44 68 42 56 58 64 50 4b 32 49 32 51 31 4a 75 61 57 4a 54 4f 48 5a 53 53 6a 64 4f 59 6e 45 33 65 58 6c 57 53 6e 4e 78 62 6b 35 48 65 47 31 31 53 54 4a 52 55 32 56 33 51 56 56 52 56 44 64 46 52 44 52 4b 4e 6c 70 7a 61 45 64 34 5a 6e 59 33 55 55 35 52 54 56 6b 76 56 54 4d 79 4f 54 56 56 56 6c 64 78 56 57 6c 79 56 44 4e 4b 61 32 39 77 51 7a 46 58 51 31 56 4a 52 6d 74 4f 62 30 64 35 56 55 70 49 57 6b 6c 48 64 30 64 4f 52 6b 56 44 51 32 68 4e 4d 54 4e 4d 62 58
                  Data Ascii: lV0dNcjByeTZWOWFXOGVwS2tIbHhmK0IyKzU1SnhUbXluSTErSmRpeGpHS2tTaFpuZUxybWczYnAxS0NGLytWclZlMzNTcitNV2R0UDhBVXdPK2I2Q1JuaWJTOHZSSjdOYnE3eXlWSnNxbk5HeG11STJRU2V3QVVRVDdFRDRKNlpzaEd4ZnY3UU5RTVkvVTMyOTVVVldxVWlyVDNKa29wQzFXQ1VJRmtOb0d5VUpIWklHd0dORkVDQ2hNMTNMbX
                  2025-04-07 13:31:21 UTC89INData Raw: 35 33 0d 0a 55 35 4d 4d 57 39 4c 59 6d 46 73 56 7a 4a 4b 53 45 39 34 4c 30 64 50 57 6d 52 6e 56 57 78 45 59 30 78 43 4d 55 64 5a 54 47 74 47 55 6a 46 57 4e 47 4e 52 52 33 4e 36 63 33 68 58 53 6a 41 32 54 58 64 4a 4e 32 70 31 63 48 68 68 55 54 51 79 4e 45 68 42 0d 0a
                  Data Ascii: 53U5MMW9LYmFsVzJKSE94L0dPWmRnVWxEY0xCMUdZTGtGUjFWNGNRR3N6c3hXSjA2TXdJN2p1cHhhUTQyNEhB
                  2025-04-07 13:31:21 UTC1220INData Raw: 35 64 37 0d 0a 4d 6a 4a 52 62 30 4d 78 62 47 73 7a 52 7a 45 35 64 6d 35 69 54 7a 6c 56 65 46 4e 35 51 6b 35 52 59 56 5a 52 4c 30 4a 75 55 30 70 55 53 6b 35 61 62 32 78 4c 5a 31 51 32 63 6c 68 61 54 47 74 34 54 43 39 58 64 45 70 55 4d 46 45 30 4d 6b 5a 59 57 6c 5a 6a 52 54 4e 43 55 32 35 75 57 53 74 76 4f 58 52 31 52 6e 64 71 52 6d 64 43 65 46 67 72 64 32 64 6f 57 6c 46 77 53 6d 35 50 5a 6c 46 78 5a 6c 51 32 53 6b 74 68 54 58 6c 31 64 6a 41 32 54 45 39 46 54 6a 46 31 53 6b 6c 69 55 54 4a 44 55 54 4e 78 56 58 52 50 61 32 46 32 56 32 39 77 4e 32 35 71 52 56 68 4a 65 6b 31 45 55 58 4e 70 4e 58 63 30 4d 55 4e 72 56 32 46 46 4e 44 46 51 53 57 52 44 59 58 42 4f 5a 47 74 33 4d 32 46 74 62 48 6c 73 63 57 52 53 63 57 52 58 4d 6e 42 43 56 57 68 77 53 7a 6c 33 52 57
                  Data Ascii: 5d7MjJRb0MxbGszRzE5dm5iTzlVeFN5Qk5RYVZRL0JuU0pUSk5ab2xLZ1Q2clhaTGt4TC9XdEpUMFE0MkZYWlZjRTNCU25uWStvOXR1RndqRmdCeFgrd2doWlFwSm5PZlFxZlQ2SkthTXl1djA2TE9FTjF1SkliUTJDUTNxVXRPa2F2V29wN25qRVhJek1EUXNpNXc0MUNrV2FFNDFQSWRDYXBOZGt3M2FtbHlscWRScWRXMnBCVWhwSzl3RW
                  2025-04-07 13:31:21 UTC282INData Raw: 31 32 35 36 2c 31 32 35 35 2c 31 32 35 34 2c 31 32 35 33 2c 31 32 35 32 2c 31 32 35 31 2c 31 32 35 30 5d 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 73 75 62 74 79 70 65 73 22 3a 5b 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 2c 33 30 38 5d 5d 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 74 79 70 65 22 3a 5b 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 45
                  Data Ascii: 1256,1255,1254,1253,1252,1251,1250],"google:suggestsubtypes":[[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308],[3,143,362,308]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","E
                  2025-04-07 13:31:21 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.74969020.19.141.174443800C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2025-04-07 13:31:22 UTC611OUTGET /favicon.ico HTTP/1.1
                  Host: auth.berger-levrault.com
                  Connection: keep-alive
                  sec-ch-ua-platform: "Windows"
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                  sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                  sec-ch-ua-mobile: ?0
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://auth.berger-levrault.com/
                  Accept-Encoding: gzip, deflate, br, zstd
                  Accept-Language: en-US,en;q=0.9
                  2025-04-07 13:31:22 UTC95INHTTP/1.1 503 Not Found
                  cache-control: no-cache
                  content-type: text/html
                  connection: close
                  2025-04-07 13:31:22 UTC16289INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 66 72 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 42 4c 2e 53 65 63 75 72 69 74 79 20 2d 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 40 69 6d 70 6f 72 74 20 75 72 6c 28 22 64 61 74 61 3a 74 65 78 74 2f 63 73 73 3b 62 61 73
                  Data Ascii: <!DOCTYPE html><html lang="fr"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>BL.Security - Service Unavailable</title> <style type="text/css"> @import url("data:text/css;bas
                  2025-04-07 13:31:22 UTC4548INData Raw: 51 73 61 6b 74 64 66 58 34 67 69 57 51 48 36 68 38 4b 44 36 48 4d 5a 62 55 4c 67 30 45 36 39 51 6a 4e 4e 44 6c 55 69 53 6b 6d 53 5a 47 73 56 53 37 7a 63 64 70 64 63 38 70 51 77 7a 6e 45 6b 62 6d 4d 46 67 75 4f 5a 4d 49 2b 42 79 6f 58 51 64 66 33 55 4e 6a 64 2b 73 78 66 42 34 71 48 78 6c 47 63 32 62 74 30 63 32 56 68 6b 6d 4b 45 58 69 53 65 4f 78 5a 36 65 44 4d 6e 73 30 4a 47 39 4a 4f 55 32 62 43 71 6a 37 62 43 57 31 48 36 2b 67 66 75 58 58 65 50 62 73 78 5a 36 56 53 65 49 70 4a 34 58 41 6b 78 4c 33 78 73 31 34 39 70 62 67 4b 64 35 4c 35 63 75 76 45 39 68 66 32 79 35 69 36 41 5a 61 6a 4a 50 6b 4d 79 59 69 48 66 62 2b 30 34 68 36 69 49 31 39 2f 53 69 67 51 68 71 34 77 37 51 73 67 46 52 54 39 69 64 46 71 39 35 6c 47 55 49 51 6b 7a 2b 45 41 53 63 65 6a 37 54
                  Data Ascii: QsaktdfX4giWQH6h8KD6HMZbULg0E69QjNNDlUiSkmSZGsVS7zcdpdc8pQwznEkbmMFguOZMI+ByoXQdf3UNjd+sxfB4qHxlGc2bt0c2VhkmKEXiSeOxZ6eDMns0JG9JOU2bCqj7bCW1H6+gfuXXePbsxZ6VSeIpJ4XAkxL3xs149pbgKd5L5cuvE9hf2y5i6AZajJPkMyYiHfb+04h6iI19/SigQhq4w7QsgFRT9idFq95lGUIQkz+EAScej7T


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0050100MB

                  Click to jump to process

                  Target ID:0
                  Start time:09:31:12
                  Start date:07/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff778810000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:1
                  Start time:09:31:13
                  Start date:07/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1800,i,5765859814087684943,14114047180601535032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2040 /prefetch:3
                  Imagebase:0x7ff778810000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:4
                  Start time:09:31:19
                  Start date:07/04/2025
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://auth.berger-levrault.com"
                  Imagebase:0x7ff778810000
                  File size:3'388'000 bytes
                  MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly