Edit tour

Windows Analysis Report
https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png

Overview

General Information

Sample URL:https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png
Analysis ID:1658816
Infos:

Detection

Score:1
Range:0 - 100
Confidence:80%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1336 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5952 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1944,i,13602665523441911202,16192736480780144314,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2196 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6872 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.pngHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.61.112:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.61.112:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.21
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /olive/images/2.62.0/global-assets/email-templates/email-logo.png HTTP/1.1Host: docucdn-a.akamaihd.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: docucdn-a.akamaihd.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.pngAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: docucdn-a.akamaihd.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundAccept-Ranges: bytesContent-Length: 10Server: AkamaiNetStorageCache-Control: max-age=31535999Date: Mon, 07 Apr 2025 23:58:30 GMTConnection: closeX-Content-Type-Options: nosniff
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 142.250.81.228:443 -> 192.168.2.4:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.61.112:443 -> 192.168.2.4:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.61.112:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir1336_1165228862Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir1336_1165228862Jump to behavior
Source: classification engineClassification label: clean1.win@21/4@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1944,i,13602665523441911202,16192736480780144314,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2196 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1944,i,13602665523441911202,16192736480780144314,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2196 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1658816 URL: https://docucdn-a.akamaihd.... Startdate: 08/04/2025 Architecture: WINDOWS Score: 1 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49366 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 142.250.81.228, 443, 49723, 49740 GOOGLEUS United States 10->15 17 a1737.b.akamai.net 23.202.61.112, 443, 49725, 49726 AKAMAI-ASN1EU United States 10->17 19 2 other IPs or domains 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
a1737.b.akamai.net
23.202.61.112
truefalse
    high
    www.google.com
    142.250.81.228
    truefalse
      high
      docucdn-a.akamaihd.net
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.pngfalse
          high
          https://docucdn-a.akamaihd.net/favicon.icofalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            23.202.61.112
            a1737.b.akamai.netUnited States
            20940AKAMAI-ASN1EUfalse
            142.250.81.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1658816
            Start date and time:2025-04-08 01:57:24 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 2s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:21
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean1.win@21/4@4/3
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.251.40.227, 142.250.80.110, 142.250.72.110, 142.251.163.84, 142.251.40.206, 142.250.65.238, 142.250.81.238, 23.203.176.221, 199.232.214.172, 142.250.80.14, 142.250.65.206, 142.250.72.99, 142.251.41.3, 142.251.40.142, 142.251.40.174, 184.31.69.3, 52.149.20.212
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, update.googleapis.com, clients.l.google.com, c.pki.goog
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text
            Category:downloaded
            Size (bytes):10
            Entropy (8bit):3.1219280948873624
            Encrypted:false
            SSDEEP:3:OFZn:OFZn
            MD5:7605968E79D0CA095AB1231486D2B814
            SHA1:A007B420D19CEEFA840F0373E050E3B51A4AB480
            SHA-256:493FDA53120050F85836032324409BE6C6484F90A0755AE0C6A673BA7626818B
            SHA-512:769249DA7ED6C6BF5671BBC2371A6453B433226CEB8C4C2AA3604000D66647BCEC83DEE1AB64C0262FA40F923D77E23BAD2C47274D339EFFC51D904CE77072A6
            Malicious:false
            Reputation:low
            URL:https://docucdn-a.akamaihd.net/favicon.ico
            Preview:Not found.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 228 x 50, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):2684
            Entropy (8bit):7.901894652512653
            Encrypted:false
            SSDEEP:48:B/6szm5aZYbB04l/HREz9CyaY6/8Rf78BLWlvhOmjtJBvQvxnwO:BSszm8Z4RHRG6uROLWb9RQj
            MD5:B4F8F0DCDA279711CB9224C2239323D4
            SHA1:3C1B1B68CD9D2D25FF5D7FB2C7A61271DFFBF41B
            SHA-256:53D92718DD6001A4EBF49D631AB9DF5B8194E6AF220790B1D8CF57164E38C6B0
            SHA-512:E97F783AF2EECCAFD684BDDE181C1509414997D2970405CC2AD7B9182439EF471EE6BF58253E6661A7B4491DD80523CC23C4544B0F9CF5AA0E9BFF4F20E7CA92
            Malicious:false
            Reputation:low
            URL:https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png
            Preview:.PNG........IHDR.......2.....L0w.....pHYs.................sRGB.........gAMA......a.....IDATx...n....#...C.y..R .!.So..s.J.%7..@..h..v.@.[....}....^.^.*r3Z.(.C.h3?s...q.....J.......3$.$..# ..D"..*.k...(..#..$Q........o."...{.).d.n.R.e...?.t5...._....2.+..... .....B..l...yQ*.....*..2.....e.X.}.{PG.SH....J.|..#....3D.FZ.Eh...d..............3..0......?."...x......4J.-....g..a8..9B$..e8....s.q...4JF[2....a.>.~3...6B.....D4d3*......o.....r#.....=.jK...1.?...o..YW..Hdgyx.7.[.....?x.......P.........K.fT..5Y&.%CbyS\.a.a.....6..y....._`.....r..!...G<...0......B.E...=:......#.p...6........!+..!MQ....t.....m.6RhO.:..odmu@P#....m.......]...|.ndS.PU\.]..`.f.Z...?.Ds]9....F).w....... ..W.........fW.R..J..4\.d4!.d.l..h..T.Rh/.+.z..R..5.h......-.{.n..@......V.k]..RR.H....(.+...C.MIl.\.LDG....C...k*...)..H0qM.{.._..A+.'.c.....-..WY......pG....A.. .......Y)EG.#t.....(...._..H....".....>.Zl.:..g...W_[I............@=Zh.75t.9.y\...N.e|..$....6...,9..h......3..fs.'9.
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 74
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 8, 2025 01:58:16.546391010 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 01:58:23.093868971 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:23.405620098 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:24.094738960 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:25.371320963 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:26.154961109 CEST4968180192.168.2.42.17.190.73
            Apr 8, 2025 01:58:27.677382946 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:27.677429914 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:27.677618027 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:27.677793026 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:27.677820921 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:27.780070066 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:27.886815071 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:27.886883020 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:27.887901068 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:27.887912989 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:27.888238907 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:27.936867952 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:29.552403927 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.552442074 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.552536964 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.552833080 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.552932024 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.552932978 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.552947044 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.553035021 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.553219080 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.553261995 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.747061968 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.747287989 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.748120070 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.748145103 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.748378038 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.748606920 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.749152899 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.749218941 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.750055075 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.750061989 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.750267982 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.792337894 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.798047066 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.933289051 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.933305979 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.933392048 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.933454037 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.933779001 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.933856964 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.934189081 CEST49726443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:29.934221983 CEST4434972623.202.61.112192.168.2.4
            Apr 8, 2025 01:58:29.996443033 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:30.044276953 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:30.942940950 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:30.943006992 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:30.943151951 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:30.944960117 CEST49725443192.168.2.423.202.61.112
            Apr 8, 2025 01:58:30.944976091 CEST4434972523.202.61.112192.168.2.4
            Apr 8, 2025 01:58:31.827608109 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:32.139847040 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:32.592978001 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:32.764843941 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:33.972220898 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:35.537050962 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.537575006 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.537720919 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.636039972 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.636472940 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.636888981 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.637350082 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.637415886 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.637449026 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.637502909 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.638123989 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.639668941 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.639682055 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.639734983 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.639767885 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.649936914 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.737287045 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.749056101 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.751301050 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.751312971 CEST44349709131.253.33.254192.168.2.4
            Apr 8, 2025 01:58:35.751368046 CEST49709443192.168.2.4131.253.33.254
            Apr 8, 2025 01:58:35.759196043 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:35.759489059 CEST49732443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:35.759526014 CEST44349732204.79.197.222192.168.2.4
            Apr 8, 2025 01:58:35.759582996 CEST49732443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:35.761296034 CEST49732443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:35.761312962 CEST44349732204.79.197.222192.168.2.4
            Apr 8, 2025 01:58:36.051086903 CEST44349732204.79.197.222192.168.2.4
            Apr 8, 2025 01:58:36.051158905 CEST49732443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:36.062150002 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:36.374808073 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:36.671211004 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:37.876427889 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:37.888464928 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:37.888617039 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:37.888684988 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:38.096745968 CEST49723443192.168.2.4142.250.81.228
            Apr 8, 2025 01:58:38.096787930 CEST44349723142.250.81.228192.168.2.4
            Apr 8, 2025 01:58:40.280397892 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:41.186621904 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:42.202286959 CEST49671443192.168.2.4204.79.197.203
            Apr 8, 2025 01:58:45.092406034 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:58:50.788261890 CEST49678443192.168.2.420.189.173.27
            Apr 8, 2025 01:58:54.713553905 CEST49680443192.168.2.4204.79.197.222
            Apr 8, 2025 01:59:07.212810040 CEST8049710208.89.73.21192.168.2.4
            Apr 8, 2025 01:59:07.212939024 CEST4971080192.168.2.4208.89.73.21
            Apr 8, 2025 01:59:27.641155958 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:27.641179085 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:27.641246080 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:27.641494989 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:27.641504049 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:27.844688892 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:27.845019102 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:27.845046997 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:37.853137970 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:37.853296041 CEST44349740142.250.81.228192.168.2.4
            Apr 8, 2025 01:59:37.853456020 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:38.095072031 CEST49740443192.168.2.4142.250.81.228
            Apr 8, 2025 01:59:38.095086098 CEST44349740142.250.81.228192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 8, 2025 01:58:23.851852894 CEST53493661.1.1.1192.168.2.4
            Apr 8, 2025 01:58:23.991430044 CEST53574381.1.1.1192.168.2.4
            Apr 8, 2025 01:58:26.030792952 CEST53522711.1.1.1192.168.2.4
            Apr 8, 2025 01:58:27.577980995 CEST5253953192.168.2.41.1.1.1
            Apr 8, 2025 01:58:27.578099966 CEST5312253192.168.2.41.1.1.1
            Apr 8, 2025 01:58:27.675646067 CEST53525391.1.1.1192.168.2.4
            Apr 8, 2025 01:58:27.676636934 CEST53531221.1.1.1192.168.2.4
            Apr 8, 2025 01:58:29.452334881 CEST5038053192.168.2.41.1.1.1
            Apr 8, 2025 01:58:29.452616930 CEST6207653192.168.2.41.1.1.1
            Apr 8, 2025 01:58:29.551310062 CEST53503801.1.1.1192.168.2.4
            Apr 8, 2025 01:58:29.551588058 CEST53620761.1.1.1192.168.2.4
            Apr 8, 2025 01:58:43.019747972 CEST53648871.1.1.1192.168.2.4
            Apr 8, 2025 01:59:01.866353989 CEST53525161.1.1.1192.168.2.4
            Apr 8, 2025 01:59:23.651402950 CEST53642821.1.1.1192.168.2.4
            Apr 8, 2025 01:59:24.458651066 CEST53529271.1.1.1192.168.2.4
            Apr 8, 2025 01:59:25.317018032 CEST53596821.1.1.1192.168.2.4
            Apr 8, 2025 01:59:31.269900084 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 8, 2025 01:58:27.577980995 CEST192.168.2.41.1.1.10x54bbStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 8, 2025 01:58:27.578099966 CEST192.168.2.41.1.1.10x3fe5Standard query (0)www.google.com65IN (0x0001)false
            Apr 8, 2025 01:58:29.452334881 CEST192.168.2.41.1.1.10x59c1Standard query (0)docucdn-a.akamaihd.netA (IP address)IN (0x0001)false
            Apr 8, 2025 01:58:29.452616930 CEST192.168.2.41.1.1.10xd415Standard query (0)docucdn-a.akamaihd.net65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 8, 2025 01:58:27.675646067 CEST1.1.1.1192.168.2.40x54bbNo error (0)www.google.com142.250.81.228A (IP address)IN (0x0001)false
            Apr 8, 2025 01:58:27.676636934 CEST1.1.1.1192.168.2.40x3fe5No error (0)www.google.com65IN (0x0001)false
            Apr 8, 2025 01:58:29.551310062 CEST1.1.1.1192.168.2.40x59c1No error (0)docucdn-a.akamaihd.netdocucdn-a.akamaihd.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
            Apr 8, 2025 01:58:29.551310062 CEST1.1.1.1192.168.2.40x59c1No error (0)docucdn-a.akamaihd.net.edgesuite.neta1737.b.akamai.netCNAME (Canonical name)IN (0x0001)false
            Apr 8, 2025 01:58:29.551310062 CEST1.1.1.1192.168.2.40x59c1No error (0)a1737.b.akamai.net23.202.61.112A (IP address)IN (0x0001)false
            Apr 8, 2025 01:58:29.551310062 CEST1.1.1.1192.168.2.40x59c1No error (0)a1737.b.akamai.net23.202.61.116A (IP address)IN (0x0001)false
            Apr 8, 2025 01:58:29.551588058 CEST1.1.1.1192.168.2.40xd415No error (0)docucdn-a.akamaihd.netdocucdn-a.akamaihd.net.edgesuite.netCNAME (Canonical name)IN (0x0001)false
            Apr 8, 2025 01:58:29.551588058 CEST1.1.1.1192.168.2.40xd415No error (0)docucdn-a.akamaihd.net.edgesuite.neta1737.b.akamai.netCNAME (Canonical name)IN (0x0001)false
            • docucdn-a.akamaihd.net
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44972623.202.61.1124435952C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 23:58:29 UTC736OUTGET /olive/images/2.62.0/global-assets/email-templates/email-logo.png HTTP/1.1
            Host: docucdn-a.akamaihd.net
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 23:58:29 UTC374INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Type: image/png
            ETag: "b4f8f0dcda279711cb9224c2239323d4:1712846771.247076"
            Last-Modified: Thu, 11 Apr 2024 14:46:11 GMT
            Server: AkamaiNetStorage
            Content-Length: 2684
            Cache-Control: max-age=26803025
            Date: Mon, 07 Apr 2025 23:58:29 GMT
            Connection: close
            Access-Control-Allow-Origin: *
            X-Content-Type-Options: nosniff
            2025-04-07 23:58:29 UTC2684INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 e4 00 00 00 32 08 06 00 00 00 4c 30 77 bf 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 0a 11 49 44 41 54 78 01 ed 9d cf 6e 1c b7 1d c7 bf 23 db 01 ea 43 bb 79 03 e6 52 20 e8 21 9b 53 6f 11 dd 73 d1 4a c9 25 37 8f 9f 40 ce 13 68 f4 04 76 9e 40 a3 5b 80 04 f0 0a 7d 00 8d f2 02 5e f7 5e 88 2a 72 33 5a ab 28 90 43 fe 68 33 3f 73 88 dd 9d fd 71 86 e4 cc ee ce 4a fc 00 c4 da 1c 0e 7f 33 24 7f 24 7f e4 8f 23 20 12 89 44 22 91 c8 2a 89 6b c2 d9 e7 9f bf 28 7f 9e 23 1c 85 24 51 98 cd ce f1 c1 07 93 e4 9b 6f 14 22 91 c8 12 7b ce 29 93 64 8c 6e 88 52 19 65 f9 fb 02 3f fd 74 35 fb e2 8b d3 d9 97 5f 0a
            Data Ascii: PNGIHDR2L0wpHYssRGBgAMAaIDATxn#CyR !SosJ%7@hv@[}^^*r3Z(Ch3?sqJ3$$# D"*k(#$Qo"{)dnRe?t5_


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44972523.202.61.1124435952C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-07 23:58:29 UTC671OUTGET /favicon.ico HTTP/1.1
            Host: docucdn-a.akamaihd.net
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-07 23:58:30 UTC216INHTTP/1.1 404 Not Found
            Accept-Ranges: bytes
            Content-Length: 10
            Server: AkamaiNetStorage
            Cache-Control: max-age=31535999
            Date: Mon, 07 Apr 2025 23:58:30 GMT
            Connection: close
            X-Content-Type-Options: nosniff
            2025-04-07 23:58:30 UTC10INData Raw: 4e 6f 74 20 66 6f 75 6e 64 0a
            Data Ascii: Not found


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:19:58:19
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:19:58:21
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1944,i,13602665523441911202,16192736480780144314,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2196 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:19:58:28
            Start date:07/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docucdn-a.akamaihd.net/olive/images/2.62.0/global-assets/email-templates/email-logo.png"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly