Edit tour

Windows Analysis Report
Adjuntos-20250407-074048.PDF.html

Overview

General Information

Sample name:Adjuntos-20250407-074048.PDF.html
Analysis ID:1658588
MD5:ca06024e57b7f9eb7dcbb18dcb3f08c1
SHA1:ca34af26a5b2edd23adbab18e8bdedc4e7f9843e
SHA256:1d46abcf3aad5cf106a237a6b77cbd594542831defab4f24ad3b1006cc143dad
Infos:

Detection

Score:22
Range:0 - 100
Confidence:80%

Signatures

HTML IFrame injector detected
Creates files inside the system directory
Deletes files inside the Windows folder
HTML page contains hidden javascript code
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4748 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,7372173933684620488,6690907252171264490,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2336 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Adjuntos-20250407-074048.PDF.html" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.htmlHTTP Parser: New IFrame, src: data:text/html;base64,PCFET0NUWVBFIGh0bWw+DQo8aHRtbCBsYW5nPSJwdC1iciI+DQo8aGVhZD4NCiAgICA8bWV0YSBjaGFyc2V0PSJVVEYtOCI+DQogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNvbnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPg0KICAgIDxtZXRhIGh0dHAtZXF1aXY9InJlZnJlc2giIGNvbnRlbnQ9IjA7dXJsPWh0dHBzOi8vZzIuY29udGFjdHN3ZWJhY2Npb24uc2l0ZS8yNTAzLyI+DQo8L2hlYWQ+DQo8Ym9keT4NCiAgICA8cD48L3A+DQo8L2JvZHk+DQo8L2h0bWw+
Source: file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.htmlHTTP Parser: Base64 decoded: <!DOCTYPE html><html lang="pt-br"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="refresh" content="0;url=https://g2.contactswebaccion.site/2503/"></head><body>...
Source: file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.72.100:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.65.227
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /2503/ HTTP/1.1Host: g2.contactswebaccion.siteConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: g2.contactswebaccion.site
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0 HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 398Content-Type: application/reports+jsonOrigin: https://g2.contactswebaccion.siteUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 07 Apr 2025 17:24:25 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeX-Frame-Options: SAMEORIGINReferrer-Policy: same-originCache-Control: max-age=15Expires: Mon, 07 Apr 2025 17:24:40 GMTReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 92cb37e8ae0f5541-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=108893&min_rtt=108371&rtt_var=23348&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2856&recv_bytes=1270&delivery_rate=34341&cwnd=243&unsent_bytes=0&cid=80edd26feac758c6&ts=492&x=0"
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownHTTPS traffic detected: 142.250.72.100:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49734 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir5428_1096968468Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir5428_1096968468Jump to behavior
Source: classification engineClassification label: sus22.phis.winHTML@23/0@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,7372173933684620488,6690907252171264490,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2336 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Adjuntos-20250407-074048.PDF.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,7372173933684620488,6690907252171264490,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2336 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1658588 Sample: Adjuntos-20250407-074048.PDF.html Startdate: 07/04/2025 Architecture: WINDOWS Score: 22 24 HTML IFrame injector detected 2->24 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 14 192.168.2.24 unknown unknown 6->14 16 192.168.2.4, 138, 443, 49541 unknown unknown 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 142.250.72.100, 443, 49723, 49742 GOOGLEUS United States 11->18 20 a.nel.cloudflare.com 35.190.80.1, 443, 49727, 49731 GOOGLEUS United States 11->20 22 g2.contactswebaccion.site 104.21.32.1, 443, 49726 CLOUDFLARENETUS United States 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.html0%Avira URL Cloudsafe
https://g2.contactswebaccion.site/2503/0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
g2.contactswebaccion.site
104.21.32.1
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      www.google.com
      142.250.72.100
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        file:///C:/Users/user/Desktop/Adjuntos-20250407-074048.PDF.htmltrue
        • Avira URL Cloud: safe
        unknown
        http://c.pki.goog/r/gsr1.crlfalse
          high
          http://c.pki.goog/r/r4.crlfalse
            high
            https://g2.contactswebaccion.site/2503/false
            • Avira URL Cloud: safe
            unknown
            https://a.nel.cloudflare.com/report/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0false
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              104.21.32.1
              g2.contactswebaccion.siteUnited States
              13335CLOUDFLARENETUSfalse
              142.250.72.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              35.190.80.1
              a.nel.cloudflare.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              192.168.2.24
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1658588
              Start date and time:2025-04-07 19:23:20 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 5m 12s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowshtmlcookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:21
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:Adjuntos-20250407-074048.PDF.html
              Detection:SUS
              Classification:sus22.phis.winHTML@23/0@6/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .html
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.251.41.3, 142.251.40.110, 142.251.16.84, 142.251.41.14, 142.250.80.110, 142.251.32.110, 23.203.176.221, 23.210.73.5, 142.251.35.174, 142.250.65.206, 142.250.80.14, 142.250.65.238, 142.251.40.142, 142.250.81.227, 142.250.176.206, 142.250.64.78, 142.250.176.195, 142.250.80.78, 142.251.40.238, 184.31.69.3, 52.149.20.212
              • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, update.googleapis.com, clients.l.google.com, c.pki.goog
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenFile calls found.
              No simulations
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              104.21.32.1Shipping Documents.exeGet hashmaliciousFormBook, PureLog StealerBrowse
              • www.6644win.mom/hs6j/
              eoIIBcxUj3.exeGet hashmaliciousFormBookBrowse
              • www.sigaque.today/n61y/
              Invoice & Packing list For Sea Shipment.exeGet hashmaliciousFormBookBrowse
              • www.itiz.xyz/a03d/?06A=1S/Ml8MhhZcgUxSbm7ZuM2rP7Vmm5l/lyuGuBD/BitQWsLFnZM8smPnB3Q7M7Y+/UA9Kc3248g==&wZAD=pBZTFP-XZbx0Fd1P
              ur3RqLz9DB.exeGet hashmaliciousFormBookBrowse
              • www.meshki-co-uk.shop/b8n0/
              ORIGINA#BL-DT-MARCH-APRIL SHIPMENT.exeGet hashmaliciousFormBookBrowse
              • www.ppostealeone.shop/v25g/
              bettercontactforgreatworksgoodforbetter.htaGet hashmaliciousCobalt Strike, FormBookBrowse
              • www.meshki-co-uk.shop/b8n0/
              Greenfields Dairy Indonesia - RFQ.exeGet hashmaliciousFormBookBrowse
              • www.dramavietsub.net/xn0a/
              KTUlWpH5Dh.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 469473cm.nyashware.ru/processorSqlGeneratorprivatetemp.php
              SHIPPING DETAILS_PDF.exeGet hashmaliciousFormBookBrowse
              • www.auto-total.info/3lc9/
              arGdXDmyGJ.exeGet hashmaliciousFormBookBrowse
              • www.rbopisalive.cyou/a669/
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              CLOUDFLARENETUShttps://nut.sh/ell/ed/322238/XZdE6PGet hashmaliciousHTMLPhisherBrowse
              • 172.67.193.116
              SecuriteInfo.com.Trojan.PackedNET.3297.27006.268.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
              • 104.26.13.205
              https://ljci.qoneqai.com/5ndAqJPY/Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
              • 104.21.54.203
              https://www.canva.com/design/DAGj9unWfgY/KGll2pdIZRgBhg9O0agAiA/view?utm_content=DAGj9unWfgY&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=hb08956af61Get hashmaliciousScreenConnect Tool, HTMLPhisherBrowse
              • 172.67.74.152
              https://t.co/ua9LgoWzzYGet hashmaliciousHTMLPhisherBrowse
              • 172.67.214.31
              http://statefinancial.comGet hashmaliciousUnknownBrowse
              • 104.17.25.14
              https://e-zpass.com-dlk.top/usGet hashmaliciousUnknownBrowse
              • 104.21.69.36
              2PBENi6LUf.exeGet hashmaliciousUnknownBrowse
              • 172.67.129.178
              https://www.google.com/url?q=https://villemonteil-my.sharepoint.com/:b:/g/personal/jerome_lassince_villemonteilaquitaine_fr/ES2_j_QZ4phKlfTEI8NeZ1kBC_b5oFLt_ua02wACxZi9Zg&source=gmail&ust=1744104792241000&usg=AOvVaw0zD3X5FizCnSCzMz7NmTiRGet hashmaliciousUnknownBrowse
              • 1.1.1.1
              https://www.jampedals.com/ajax/change-currency.php?cur=EUR&ref=http%3A%2F%2Fassets-usa.mkt.dynamics.com/cf802bab-390f-f011-9aed-6045bd003e0f/digitalassets/standaloneforms/c2a09290-4e0f-f011-9988-6045bd02012aGet hashmaliciousUnknownBrowse
              • 162.159.140.229
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              28a2c9bd18a11de089ef85a160da29e4uOZ3Iu4I6x.exeGet hashmaliciousMSIL Logger, MassLogger RAT, XRedBrowse
              • 204.79.197.222
              RE_01890389024s1.pdf.wsfGet hashmaliciousKoadicBrowse
              • 204.79.197.222
              YTOEOXNI.msiGet hashmaliciousRedLine, SectopRATBrowse
              • 204.79.197.222
              MinecraftLauncher.exeGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              https://www.templatent.com/eur/Error/PageExpiredGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              http://url1564.centology.io/ls/click?upn=u001.d2RZm3sdsAkY6VWRfEGVYhhd03nsx1fxVdPCzzYZjVs-3DeNyb_A3nRQoop3xGTTNLdbAlLJQGdPMUE-2FZDYqtqfILcMWbKBUj6aSzky5kkqef1RBYYHfFIyidUyrILF06nLVobXXvMFQcp1-2B2z97T3imW2egDqBfKltwn6Hg9yK3iFRk8gweCxaa5z1PwPy3y2Y8JlPqa4ITNqAx0fR2ufQZRr1BbGXx14rQr1v96no27v1n3SNll-2B0Wbgq4XCBUyUFt-2FNLpw-3D-3DGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              https://rapiddevapi.com/M3P2n8Uaz6wsh7s2fgSRwIiSadn4Wz1fNsRbVwXrWGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              https://topdogcaretips.com/%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20X/Get hashmaliciousUnknownBrowse
              • 204.79.197.222
              RE_00834473899387474.pdf.wsfGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              http://www.vipbox.lcGet hashmaliciousUnknownBrowse
              • 204.79.197.222
              No context
              No created / dropped files found
              File type:HTML document, Unicode text, UTF-16, little-endian text, with very long lines (451), with CRLF line terminators
              Entropy (8bit):3.9045920563447893
              TrID:
              • Text - UTF-16 (LE) encoded (2002/1) 64.44%
              • MP3 audio (1001/1) 32.22%
              • Lumena CEL bitmap (63/63) 2.03%
              • Corel Photo Paint (41/41) 1.32%
              File name:Adjuntos-20250407-074048.PDF.html
              File size:1'894 bytes
              MD5:ca06024e57b7f9eb7dcbb18dcb3f08c1
              SHA1:ca34af26a5b2edd23adbab18e8bdedc4e7f9843e
              SHA256:1d46abcf3aad5cf106a237a6b77cbd594542831defab4f24ad3b1006cc143dad
              SHA512:04d15086adfd82403ea0e84d3ca3c93d39b8d9de46eb441cd5e5c83e1e744c2398d8f6f755037125fc078fb32ae2e0152a3aff4ef521b96f72f8100969fd5ee3
              SSDEEP:48:RByGSB2B+B+BuBp9462dfbEybjbB6GSBuB+B+BuB0:1X9B
              TLSH:7B4183177FD90026617A564CABF2807753ADA861A17C4C4421989705CADBE13CD22FF7
              File Content Preview:..<.!.-.-. .4.2.0.3. .-.-.>.....<.!.-.-.<.p.>.7.4.6.4.:. .4.2.0.3.<./.p.>. .-.-.>.....<.!.-.-.<.p.>.5.4.4.0.:. .5.4.4.0.<./.p.>. .-.-.>.....<.!.-.-.<.p.>.9.4.6.7.:. .9.4.6.7.<./.p.>.-.-.>.....<.!.-.-.<.p.>.3.9.9.9.:. .3.9.9.9.<./.p.>.-.-.>.....<.!.-.-.<.p

              Download Network PCAP: filteredfull

              • Total Packets: 96
              • 443 (HTTPS)
              • 80 (HTTP)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Apr 7, 2025 19:24:11.580073118 CEST4968180192.168.2.42.17.190.73
              Apr 7, 2025 19:24:18.456602097 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:18.777486086 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:19.439131021 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:20.727209091 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:21.189070940 CEST4968180192.168.2.42.17.190.73
              Apr 7, 2025 19:24:21.424619913 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:21.424712896 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:21.424870968 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:21.425152063 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:21.425187111 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:21.644738913 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:21.645004988 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:21.646068096 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:21.646091938 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:21.646363974 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:21.689223051 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:23.142002106 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:24.429773092 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.429853916 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:24.431077957 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.431077957 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.431154013 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:24.665239096 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:24.665472031 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.666630030 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.666639090 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:24.666903973 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:24.670258999 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:24.712277889 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141181946 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141226053 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141268015 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141283035 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:25.141288996 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141333103 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141367912 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:25.141503096 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.141554117 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:25.157548904 CEST49726443192.168.2.4104.21.32.1
              Apr 7, 2025 19:24:25.157579899 CEST44349726104.21.32.1192.168.2.4
              Apr 7, 2025 19:24:25.262943029 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.263035059 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.263148069 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.263561010 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.263578892 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.480072021 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.480168104 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.481834888 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.481863976 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.482115984 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.482556105 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.524297953 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.715492964 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.715578079 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.715640068 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.715905905 CEST49727443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.715945959 CEST4434972735.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.716721058 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.716797113 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.716886997 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.717154026 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.717185974 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.927331924 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.927862883 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.927887917 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:25.928349972 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:25.928356886 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:26.163515091 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:26.163583994 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:26.163906097 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:26.165719032 CEST49731443192.168.2.435.190.80.1
              Apr 7, 2025 19:24:26.165735006 CEST4434973135.190.80.1192.168.2.4
              Apr 7, 2025 19:24:27.220761061 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:27.532825947 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:27.954735041 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:28.136382103 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:29.344952106 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:30.212125063 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.215928078 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.215928078 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.320055962 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.320982933 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.321039915 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.321192980 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.322139978 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.324614048 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.324826002 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.326632023 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.326940060 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.326947927 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.330857038 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.338150024 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.427205086 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.443059921 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.445441008 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.445450068 CEST44349709131.253.33.254192.168.2.4
              Apr 7, 2025 19:24:30.445688963 CEST49709443192.168.2.4131.253.33.254
              Apr 7, 2025 19:24:30.459615946 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.459908009 CEST49734443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.459990978 CEST44349734204.79.197.222192.168.2.4
              Apr 7, 2025 19:24:30.460272074 CEST49734443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.460272074 CEST49734443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.460345984 CEST44349734204.79.197.222192.168.2.4
              Apr 7, 2025 19:24:30.660617113 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:30.760727882 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:24:30.761112928 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:30.761219978 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:30.767740965 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.774619102 CEST44349734204.79.197.222192.168.2.4
              Apr 7, 2025 19:24:30.774791002 CEST49734443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:30.862534046 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:24:30.867922068 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:24:30.867932081 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:24:30.868123055 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:30.873801947 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:30.975559950 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:24:31.016829967 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:24:31.377024889 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:31.675038099 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:31.675102949 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:31.675144911 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:31.752008915 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:32.535289049 CEST49723443192.168.2.4142.250.72.100
              Apr 7, 2025 19:24:32.535312891 CEST44349723142.250.72.100192.168.2.4
              Apr 7, 2025 19:24:32.580231905 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:34.985562086 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:36.565778971 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:37.562079906 CEST49671443192.168.2.4204.79.197.203
              Apr 7, 2025 19:24:39.798116922 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:24:46.175856113 CEST49678443192.168.2.420.189.173.27
              Apr 7, 2025 19:24:49.416822910 CEST49680443192.168.2.4204.79.197.222
              Apr 7, 2025 19:25:21.346923113 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:21.346982956 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:21.347053051 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:21.347243071 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:21.347258091 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:21.561047077 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:21.561362028 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:21.561383963 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:31.314625025 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:25:31.419089079 CEST8049735142.250.65.227192.168.2.4
              Apr 7, 2025 19:25:31.419137955 CEST4973580192.168.2.4142.250.65.227
              Apr 7, 2025 19:25:31.581784010 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:31.581845045 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:25:31.581949949 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:32.535507917 CEST49742443192.168.2.4142.250.72.100
              Apr 7, 2025 19:25:32.535538912 CEST44349742142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:01.658232927 CEST49708443192.168.2.452.113.196.254
              Apr 7, 2025 19:26:21.409845114 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:21.409893036 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:21.409991980 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:21.410237074 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:21.410254002 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:21.619549990 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:21.619992018 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:21.620023966 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:31.650197029 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:31.650255919 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:31.650584936 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:32.534750938 CEST49756443192.168.2.4142.250.72.100
              Apr 7, 2025 19:26:32.534780979 CEST44349756142.250.72.100192.168.2.4
              Apr 7, 2025 19:26:38.166421890 CEST44349709131.253.33.254192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 7, 2025 19:24:18.570846081 CEST53565701.1.1.1192.168.2.4
              Apr 7, 2025 19:24:18.597888947 CEST53604511.1.1.1192.168.2.4
              Apr 7, 2025 19:24:19.374511957 CEST53528151.1.1.1192.168.2.4
              Apr 7, 2025 19:24:19.596710920 CEST53495411.1.1.1192.168.2.4
              Apr 7, 2025 19:24:21.284204006 CEST5014353192.168.2.41.1.1.1
              Apr 7, 2025 19:24:21.289783955 CEST5964453192.168.2.41.1.1.1
              Apr 7, 2025 19:24:21.389414072 CEST53501431.1.1.1192.168.2.4
              Apr 7, 2025 19:24:24.293910980 CEST5343353192.168.2.41.1.1.1
              Apr 7, 2025 19:24:24.299721003 CEST5174353192.168.2.41.1.1.1
              Apr 7, 2025 19:24:24.418653965 CEST53534331.1.1.1192.168.2.4
              Apr 7, 2025 19:24:24.427635908 CEST53517431.1.1.1192.168.2.4
              Apr 7, 2025 19:24:25.145028114 CEST6008753192.168.2.41.1.1.1
              Apr 7, 2025 19:24:25.145239115 CEST5749553192.168.2.41.1.1.1
              Apr 7, 2025 19:24:25.254097939 CEST53600871.1.1.1192.168.2.4
              Apr 7, 2025 19:24:25.254800081 CEST53574951.1.1.1192.168.2.4
              Apr 7, 2025 19:24:36.534032106 CEST53634891.1.1.1192.168.2.4
              Apr 7, 2025 19:24:55.403995037 CEST53592621.1.1.1192.168.2.4
              Apr 7, 2025 19:25:17.023845911 CEST53547401.1.1.1192.168.2.4
              Apr 7, 2025 19:25:17.828681946 CEST53608821.1.1.1192.168.2.4
              Apr 7, 2025 19:25:19.828593016 CEST53618501.1.1.1192.168.2.4
              Apr 7, 2025 19:25:26.680370092 CEST138138192.168.2.4192.168.2.255
              Apr 7, 2025 19:25:48.796175957 CEST53591171.1.1.1192.168.2.4
              Apr 7, 2025 19:26:34.155180931 CEST53530921.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 7, 2025 19:24:21.284204006 CEST192.168.2.41.1.1.10x5faeStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:21.289783955 CEST192.168.2.41.1.1.10x9d95Standard query (0)www.google.com65IN (0x0001)false
              Apr 7, 2025 19:24:24.293910980 CEST192.168.2.41.1.1.10x5fdeStandard query (0)g2.contactswebaccion.siteA (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.299721003 CEST192.168.2.41.1.1.10x798aStandard query (0)g2.contactswebaccion.site65IN (0x0001)false
              Apr 7, 2025 19:24:25.145028114 CEST192.168.2.41.1.1.10xe690Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:25.145239115 CEST192.168.2.41.1.1.10x7882Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 7, 2025 19:24:21.389414072 CEST1.1.1.1192.168.2.40x5faeNo error (0)www.google.com142.250.72.100A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.32.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.80.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.112.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.96.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.16.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.64.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.418653965 CEST1.1.1.1192.168.2.40x5fdeNo error (0)g2.contactswebaccion.site104.21.48.1A (IP address)IN (0x0001)false
              Apr 7, 2025 19:24:24.427635908 CEST1.1.1.1192.168.2.40x798aNo error (0)g2.contactswebaccion.site65IN (0x0001)false
              Apr 7, 2025 19:24:25.254097939 CEST1.1.1.1192.168.2.40xe690No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
              • g2.contactswebaccion.site
              • a.nel.cloudflare.com
              • c.pki.goog
              Session IDSource IPSource PortDestination IPDestination Port
              0192.168.2.449735142.250.65.22780
              TimestampBytes transferredDirectionData
              Apr 7, 2025 19:24:30.761219978 CEST202OUTGET /r/gsr1.crl HTTP/1.1
              Cache-Control: max-age = 3000
              Connection: Keep-Alive
              Accept: */*
              If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
              User-Agent: Microsoft-CryptoAPI/10.0
              Host: c.pki.goog
              Apr 7, 2025 19:24:30.867922068 CEST1254INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
              Cross-Origin-Resource-Policy: cross-origin
              Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
              Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
              Content-Length: 1739
              X-Content-Type-Options: nosniff
              Server: sffe
              X-XSS-Protection: 0
              Date: Mon, 07 Apr 2025 17:12:58 GMT
              Expires: Mon, 07 Apr 2025 18:02:58 GMT
              Cache-Control: public, max-age=3000
              Age: 692
              Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
              Content-Type: application/pkix-crl
              Vary: Accept-Encoding
              Data Raw: 30 82 06 c7 30 82 05 af 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69 67 6e 20 6e 76 2d 73 61 31 10 30 0e 06 03 55 04 0b 13 07 52 6f 6f 74 20 43 41 31 1b 30 19 06 03 55 04 03 13 12 47 6c 6f 62 61 6c 53 69 67 6e 20 52 6f 6f 74 20 43 41 17 0d 32 35 30 34 30 37 30 30 30 30 30 30 5a 17 0d 32 35 30 37 31 35 30 30 30 30 30 30 5a 30 82 04 f1 30 2a 02 0b 04 00 00 00 00 01 1e 44 a5 e4 04 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 29 45 c3 a8 0f 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 20 19 c1 8d 68 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2c 5e 7f 1a 88 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 15 4b 5a [TRUNCATED]
              Data Ascii: 000*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA250407000000Z250715000000Z00*D141125000000Z00U0*)E141125000000Z00U0* h141125000000Z00U0*,^141125000000Z00U0*KZ160107000000Z00U0*/NIR170419000000Z00U0*/NG170419000000Z00U0*/N9191120000000Z00U0*/N=k191204000000Z00U
              Apr 7, 2025 19:24:30.867932081 CEST1198INData Raw: 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2f 4e e1 3b 58 17 0d 31 39 31 32 30 34 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2d 02 0e 47 c3 0f ff 8a 61 9a 37 f5 a8 2e f0 b5 75 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30
              Data Ascii: 0*/N;X191204000000Z00U0-Ga7.u200630000000Z00U0-GA>ThA200630000000Z00U0-GK&TA+200630000000Z00U0*6::200711160000Z00U0/vSBS
              Apr 7, 2025 19:24:30.873801947 CEST200OUTGET /r/r4.crl HTTP/1.1
              Cache-Control: max-age = 3000
              Connection: Keep-Alive
              Accept: */*
              If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
              User-Agent: Microsoft-CryptoAPI/10.0
              Host: c.pki.goog
              Apr 7, 2025 19:24:30.975559950 CEST1243INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
              Cross-Origin-Resource-Policy: cross-origin
              Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
              Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
              Content-Length: 530
              X-Content-Type-Options: nosniff
              Server: sffe
              X-XSS-Protection: 0
              Date: Mon, 07 Apr 2025 16:50:53 GMT
              Expires: Mon, 07 Apr 2025 17:40:53 GMT
              Cache-Control: public, max-age=3000
              Age: 2017
              Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
              Content-Type: application/pkix-crl
              Vary: Accept-Encoding
              Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
              Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449726104.21.32.14434748C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-07 17:24:24 UTC698OUTGET /2503/ HTTP/1.1
              Host: g2.contactswebaccion.site
              Connection: keep-alive
              sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: cross-site
              Sec-Fetch-Mode: navigate
              Sec-Fetch-Dest: iframe
              Sec-Fetch-Storage-Access: active
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-07 17:24:25 UTC911INHTTP/1.1 403 Forbidden
              Date: Mon, 07 Apr 2025 17:24:25 GMT
              Content-Type: text/html; charset=UTF-8
              Transfer-Encoding: chunked
              Connection: close
              X-Frame-Options: SAMEORIGIN
              Referrer-Policy: same-origin
              Cache-Control: max-age=15
              Expires: Mon, 07 Apr 2025 17:24:40 GMT
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 92cb37e8ae0f5541-EWR
              alt-svc: h3=":443"; ma=86400
              server-timing: cfL4;desc="?proto=TCP&rtt=108893&min_rtt=108371&rtt_var=23348&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2856&recv_bytes=1270&delivery_rate=34341&cwnd=243&unsent_bytes=0&cid=80edd26feac758c6&ts=492&x=0"
              2025-04-07 17:24:25 UTC458INData Raw: 31 31 61 62 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 21 2d 2d 5b 69 66 20 6c 74 20 49 45 20 37 5d 3e 20 3c 68 74 6d 6c 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 20 69 65 36 20 6f 6c 64 69 65 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 3e 20 3c 21 5b 65 6e 64 69 66 5d 2d 2d 3e 0a 3c 21 2d 2d 5b 69 66 20 49 45 20 37 5d 3e 20 20 20 20 3c 68 74 6d 6c 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 20 69 65 37 20 6f 6c 64 69 65 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 3e 20 3c 21 5b 65 6e 64 69 66 5d 2d 2d 3e 0a 3c 21 2d 2d 5b 69 66 20 49 45 20 38 5d 3e 20 20 20 20 3c 68 74 6d 6c 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 20 69 65 38 20 6f 6c 64 69 65 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 22 3e 20 3c 21 5b 65 6e 64 69 66 5d 2d 2d 3e 0a 3c 21 2d 2d 5b 69 66 20
              Data Ascii: 11ab<!DOCTYPE html>...[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->...[if IE 7]> <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->...[if IE 8]> <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->...[if
              2025-04-07 17:24:25 UTC1369INData Raw: 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 45 64 67 65 22 20 2f 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 20 6e 6f 66 6f 6c 6c 6f 77 22 20 2f 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 69 64 3d 22 63 66 5f 73 74 79 6c 65 73 2d 63 73 73 22 20 68 72 65 66 3d 22 2f 63 64 6e 2d 63 67 69 2f 73 74 79 6c 65 73 2f 63
              Data Ascii: et=UTF-8" /><meta http-equiv="X-UA-Compatible" content="IE=Edge" /><meta name="robots" content="noindex, nofollow" /><meta name="viewport" content="width=device-width,initial-scale=1" /><link rel="stylesheet" id="cf_styles-css" href="/cdn-cgi/styles/c
              2025-04-07 17:24:25 UTC1369INData Raw: 63 66 2d 73 63 72 65 65 6e 73 68 6f 74 2d 66 75 6c 6c 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 70 61 6e 20 63 6c 61 73 73 3d 22 63 66 2d 6e 6f 2d 73 63 72 65 65 6e 73 68 6f 74 20 65 72 72 6f 72 22 3e 3c 2f 73 70 61 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 3c 2f 64 69 76 3e 3c 21 2d 2d 20 2f 2e 63 61 70 74 63 68 61 2d 63 6f 6e 74 61 69 6e 65 72 20 2d 2d 3e 0a 0a 20 20 20 20 20 20 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 66 2d 73 65 63 74 69 6f 6e 20 63 66 2d 77 72 61 70 70 65 72 22 3e 0a 20 20 20 20 20 20 20 20 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 66 2d 63 6f 6c 75 6d 6e 73 20 74 77
              Data Ascii: cf-screenshot-full"> <span class="cf-no-screenshot error"></span> </div> </div> </div>... /.captcha-container --> <div class="cf-section cf-wrapper"> <div class="cf-columns tw
              2025-04-07 17:24:25 UTC1335INData Raw: 66 2d 66 6f 6f 74 65 72 2d 69 74 65 6d 20 73 6d 3a 62 6c 6f 63 6b 20 73 6d 3a 6d 62 2d 31 22 3e 43 6c 6f 75 64 66 6c 61 72 65 20 52 61 79 20 49 44 3a 20 3c 73 74 72 6f 6e 67 20 63 6c 61 73 73 3d 22 66 6f 6e 74 2d 73 65 6d 69 62 6f 6c 64 22 3e 39 32 63 62 33 37 65 38 61 65 30 66 35 35 34 31 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 73 70 61 6e 3e 0a 20 20 20 20 3c 73 70 61 6e 20 63 6c 61 73 73 3d 22 63 66 2d 66 6f 6f 74 65 72 2d 73 65 70 61 72 61 74 6f 72 20 73 6d 3a 68 69 64 64 65 6e 22 3e 26 62 75 6c 6c 3b 3c 2f 73 70 61 6e 3e 0a 20 20 20 20 3c 73 70 61 6e 20 69 64 3d 22 63 66 2d 66 6f 6f 74 65 72 2d 69 74 65 6d 2d 69 70 22 20 63 6c 61 73 73 3d 22 63 66 2d 66 6f 6f 74 65 72 2d 69 74 65 6d 20 68 69 64 64 65 6e 20 73 6d 3a 62 6c 6f 63 6b 20 73 6d 3a 6d 62 2d 31 22
              Data Ascii: f-footer-item sm:block sm:mb-1">Cloudflare Ray ID: <strong class="font-semibold">92cb37e8ae0f5541</strong></span> <span class="cf-footer-separator sm:hidden">&bull;</span> <span id="cf-footer-item-ip" class="cf-footer-item hidden sm:block sm:mb-1"
              2025-04-07 17:24:25 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44972735.190.80.14434748C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-07 17:24:25 UTC564OUTOPTIONS /report/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0 HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Origin: https://g2.contactswebaccion.site
              Access-Control-Request-Method: POST
              Access-Control-Request-Headers: content-type
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-07 17:24:25 UTC336INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-max-age: 86400
              access-control-allow-methods: POST, OPTIONS
              access-control-allow-origin: *
              access-control-allow-headers: content-length, content-type
              date: Mon, 07 Apr 2025 17:24:25 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44973135.190.80.14434748C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2025-04-07 17:24:25 UTC539OUTPOST /report/v4?s=bvHJwjTxGrg0XLOa415Y6H2P9Nr4l6dBIhCmVb%2Br9dgtHqHkpXMaobM5BkbAg5IyIK1fYF7TjA6hTWm69mB44yFCF4kBeejTM2ypd%2BJHYlS528JM5KvixoDXRo7h%2FkBl8XBOkn5pM6%2FauIk0 HTTP/1.1
              Host: a.nel.cloudflare.com
              Connection: keep-alive
              Content-Length: 398
              Content-Type: application/reports+json
              Origin: https://g2.contactswebaccion.site
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br, zstd
              Accept-Language: en-US,en;q=0.9
              2025-04-07 17:24:25 UTC398OUTData Raw: 5b 7b 22 61 67 65 22 3a 32 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 38 34 38 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 33 32 2e 31 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 33 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 67 32 2e 63 6f 6e 74 61 63 74 73 77 65 62 61 63 63 69
              Data Ascii: [{"age":2,"body":{"elapsed_time":848,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.32.1","status_code":403,"type":"http.error"},"type":"network-error","url":"https://g2.contactswebacci
              2025-04-07 17:24:26 UTC214INHTTP/1.1 200 OK
              Content-Length: 0
              access-control-allow-origin: *
              vary: Origin
              date: Mon, 07 Apr 2025 17:24:25 GMT
              Via: 1.1 google
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Connection: close


              050100150200s020406080100

              Click to jump to process

              050100150200s0.0050100MB

              Click to jump to process

              Target ID:1
              Start time:13:24:14
              Start date:07/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:false

              Target ID:2
              Start time:13:24:15
              Start date:07/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,7372173933684620488,6690907252171264490,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2336 /prefetch:3
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:false

              Target ID:4
              Start time:13:24:23
              Start date:07/04/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Adjuntos-20250407-074048.PDF.html"
              Imagebase:0x7ff786830000
              File size:3'388'000 bytes
              MD5 hash:E81F54E6C1129887AEA47E7D092680BF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly