Edit tour

Windows Analysis Report
https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf

Overview

General Information

Sample URL:https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3S
Analysis ID:1672187
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

HTML body contains password input but no form action
HTML title does not match URL
Suricata IDS alerts with low severity for network traffic

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6732 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,14289345589960235143,3705958016247783956,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2228 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 3824 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-23T17:04:51.975997+020028236061Exploit Kit Activity Detected45.60.62.175443192.168.2.1849731TCP

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: Title: IDX - Login does not match URL
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=#{GTM-MC3VJKXG}
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=#{GTM-MC3VJKXG}
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=#{GTM-MC3VJKXG}
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=#{GTM-MC3VJKXG}
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: <input type="password" .../> found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="author".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="author".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="author".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="author".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="copyright".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="copyright".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="copyright".. found
Source: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 34.102.239.211:443 -> 192.168.2.18:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.102.239.211:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.27.152:443 -> 192.168.2.18:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.86.42:443 -> 192.168.2.18:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.18:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.86.42:443 -> 192.168.2.18:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.27.152:443 -> 192.168.2.18:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.87.42:443 -> 192.168.2.18:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49748 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49901 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 6MB later: 37MB
Source: Network trafficSuricata IDS: 2823606 - Severity 1 - ETPRO EXPLOIT_KIT Possible Evil Redirect Leading to EK Dec 04 2016 : 45.60.62.175:443 -> 192.168.2.18:49731
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.7
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf HTTP/1.1Host: email.mg.idx.usConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /data-center/personal?brand= HTTP/1.1Host: app.idx.usConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /69007daa2f.js HTTP/1.1Host: use.fontawesome.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/runtime.069f6ad593699107.js HTTP/1.1Host: app.idx.usConnection: keep-aliveOrigin: https://app.idx.ussec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==
Source: global trafficHTTP traffic detected: GET /en-US/polyfills.b3873936e16841b7.js HTTP/1.1Host: app.idx.usConnection: keep-aliveOrigin: https://app.idx.ussec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==
Source: global trafficHTTP traffic detected: GET /en-US/main.779297c0974f4c68.js HTTP/1.1Host: app.idx.usConnection: keep-aliveOrigin: https://app.idx.ussec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==
Source: global trafficHTTP traffic detected: GET /69007daa2f.css HTTP/1.1Host: use.fontawesome.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /releases/v4.7.0/css/font-awesome-css.min.css HTTP/1.1Host: use.fontawesome.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://use.fontawesome.com/69007daa2f.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/otSDKStub.js HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /consent/e8b305c7-027f-445b-955e-48b356dac2ca/e8b305c7-027f-445b-955e-48b356dac2ca.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/hashes.47ba75654ba416c6.js HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /_Incapsula_Resource?SWJIYLWA=719d34d31c8e3a6e6fffd425f7e032f3&ns=1&cb=784674985 HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /en-US/styles.1eee1ae52eb0e54a.css HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://app.idx.us/data-center/personal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /releases/v4.7.0/fonts/fontawesome-webfont.woff2 HTTP/1.1Host: use.fontawesome.comConnection: keep-aliveOrigin: https://app.idx.ussec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://use.fontawesome.com/69007daa2f.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/otBannerSdk.js HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /consent/e8b305c7-027f-445b-955e-48b356dac2ca/e8b305c7-027f-445b-955e-48b356dac2ca.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/assets/img/idx_logo.png HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /en-US/styles.1eee1ae52eb0e54a.css HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0; ___utmvc=Qy+Yq5/fY/xKcixqUVWq48eA86heNab3MshyFIYKO7QGNKZGHKUxA0FAMJnS0KMsAcRLhiS/aTiTJ/79ze87X1mv3qyatLeyBgFfhsGCg1wuhonN3wCcKEOr6bUev7/ueecjeQxCOBs9avkB69wNQ9wr2vq6MXLLbE2j/qfvy4aFXuLSactjy/QUaQTgDsXuAEjCbrb+Xo0agabalKiNDv8amQhnhnt8oLQeMJUwdYUUBMJpxZreORXYUHFZk8COMZ3X35c2WJvibSxvdec2s/dvBlA70uG4aqO5VTZz2294GYW02TkmA8Yc4vLOxTbQeklpKvWx4cCZXRF6+Ftpt96XFqrP1icRTxT/t3JUg6cKFkiJvkMX+yCtdVllW+nLGtInto2ZqrFqJdkryGb6hNQ5o8kcr8p2X06RUMA4Bgo0pgYWXDXEJe1QOK9XkYorhtxk+w+SybBX6dsttMyLZU8TaXJBERkKk5MTni9xfaMvPKkwlUiwQPBuuc1xdXfLbBuy5dCn4Xpm3hs1Jc3ul1tJ3KcF+AD5cCQiW0UQDDcGVrU3RpGJH17TDciVSdFJFEY6Lg+6qK5lDs9UAQ+eAFuJbWxldDUHQ0kFmTsLEn96dQCZqMc3B9dslV5RzIEBM48n13tXHI1HTW/TPKLk90IrO19D6WmFPXJJoehIAR4i88VfApU0MjUzwUdBYCcRfAnB34Eynpw02/DtDQy0gXrt6UHPyDKZgowzDUKz2v2hb37voXS6EVqhnIKPN37mWimjrH+Kbnh6JIdkSyLdJ1H0tRPJmZfXfg/DlNOxQc+yERA3KnzhHVl7a5lZEf+pILSKiWvKwcI/ZlsHjjAig36tt4xff53Qh48ILFsw1HtI8PKoeIZpEqwDe7xhMcfXyWOUXtCO4qzqba5dlhq3lmfmX982rCq1QuHVsLEYqx4ZkPABb2zljQun4ZQzeP0vhZJQVDpoX+VaxFz+yd5QHyvoWJGJ3SMVpVk33ri/RyHvJzPy/oNcA1jkYRZA4GTeEvnQmyfeCoRKUxsAsyonZx/ETsog3Mc8lBU2oYYj3YpsoSwhWm6cLlBYjeuu7qCiMX2vvSrlt9tUmvrPDeIW067TKqQ3TP8AKu2Iui+9YO0uad6ts5fRoalLPcViyveIyFBeoB0vOyGLuPKYYDgdCSVUWtEMItVzaO3I86pufP4hpnhpiulbUXneTajleNQUElMftLhS5ZgcjmEtwad0HVswYJZvS17EQhCRY7kYqR1sY0CWURBD4vUhARiWoHbH+8D/+iWViKbEtf+V5rzXX0ckz7fbyL/CkGiI6j8qIM2sl3RZ0KB51McrT6jmre1Ey3PkmXKyGZ9sfj7+7P5C3Nk2LH3BUSHdaXLxOpCKOuzDECc7GbsJ/VWn7ed6AjFR6pYOUncHoROnwwIuGQDV8XozLmDXTyhULCLCHILTL41HU6ifqptHz6o5QTRraUQy45hIvmcKUAAPPQVUNFjczKbGCVGstipH3ZG+D1cwJfAKFcK7PnddMY6k//R+thAu1cqutZ874nawb7Kz2ncE9BedxD6M12sNeGrsJrEkTIBHvFe7WIrBJfeZ32Ze4rhV1XOZq7Walw7+3RwiQZa/Qo0opPWpo5Vn+DVib/5oGm/SZ66PmVawZHCE8sGlzVXsxrvh+kxHag45p9O2VMyi36pKDR1LQiMFThU+0xFmRirD/8oRfkBKPtwPmqybPOmstBpVoJReHo9QLNLv8rI/sljsY0TzDTAmCMrxJmFML9dDyUxk87yj308Rx6J50T7+aBs9aNo1MyOHMHTv8C+insCRSioNrGY5a+V0khslMmgclE1QsyWtmplif/R1I+2AOPjVHXO0fztTZyRRStXVPqMvzcNmFn6CNLVN5A8lf+Z3KHTF3dQvl4cJLUME4x3YZgPDZZQr5NWpYjsYTT7FN/LbB/1IXn9JMReLFJ1vMpseCn1FakoLs/cn5OMbn1VLlDZMfvXXm5v358t6gKER5gkv//RuOyzfTwydx1wDGE37b9ilKI+5hV67YTCy4R2/u7LWtT6DNuOj/bpAM6eS1
Source: global trafficHTTP traffic detected: GET /en-US/assets/img/idx_logo.png HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /en-US/assets/img/idx_glyph_2.0.png HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /consent/e8b305c7-027f-445b-955e-48b356dac2ca/7f8bc42a-4403-43b5-80d3-6e860ef32e59/en.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/English.c8533c11959a8c72.svg HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /consent/e8b305c7-027f-445b-955e-48b356dac2ca/7f8bc42a-4403-43b5-80d3-6e860ef32e59/en.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otFloatingRoundedCorner.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/v2/otPcCenter.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otCookieSettingsButton.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otCommonStyles.css HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/assets/img/idx_glyph_2.0.png HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.0.1745420689.0.0.0
Source: global trafficHTTP traffic detected: GET /en-US/English.c8533c11959a8c72.svg HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A52+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D
Source: global trafficHTTP traffic detected: GET /en-US/assets/img/idx_logo.png HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A52+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otFloatingRoundedCorner.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otCommonStyles.css HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/otCookieSettingsButton.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_Incapsula_Resource?SWKMTFSR=1&e=0.7648125622737394 HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A52+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D
Source: global trafficHTTP traffic detected: GET /scripttemplates/202209.2.0/assets/v2/otPcCenter.json HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/static/ot_close.svg HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/e8b305c7-027f-445b-955e-48b356dac2ca/242c0063-9eef-4afd-9139-94f6cdc699c5/OneTrust_logoSize.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/2bbb96d4-2e44-4476-85a5-39074d56a5c4/349e79cb-92c6-48ea-8758-07d5f9e355d4/IDXlogo_100px.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/static/poweredBy_ot_logo.svg HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_Incapsula_Resource?SWKMTFSR=1&e=0.7648125622737394 HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A53+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D&groups=C0001%3A1%2CC0004%3A0%2CC0003%3A0%2CC0002%3A0
Source: global trafficHTTP traffic detected: GET /logos/static/ot_close.svg HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/favicon.ico?v=1 HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A53+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D&groups=C0001%3A1%2CC0004%3A0%2CC0003%3A0%2CC0002%3A0
Source: global trafficHTTP traffic detected: GET /logos/static/poweredBy_ot_logo.svg HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/e8b305c7-027f-445b-955e-48b356dac2ca/242c0063-9eef-4afd-9139-94f6cdc699c5/OneTrust_logoSize.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/2bbb96d4-2e44-4476-85a5-39074d56a5c4/349e79cb-92c6-48ea-8758-07d5f9e355d4/IDXlogo_100px.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /en-US/favicon.ico?v=1 HTTP/1.1Host: app.idx.usConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A53+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D&groups=C0001%3A1%2CC0004%3A0%2CC0003%3A0%2CC0002%3A0
Source: global trafficHTTP traffic detected: GET /en-US/favicon.ico?v=1 HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A53+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D&groups=C0001%3A1%2CC0004%3A0%2CC0003%3A0%2CC0002%3A0
Source: global trafficHTTP traffic detected: GET /en-US/favicon.ico?v=1 HTTP/1.1Host: app.idx.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2414945=vMkcDlGsTZSVM24v6gaEJY8BCWgAAAAAQUIPAAAAAAAom2QizgSRgEv5J9VA2BF5; nlbi_2414945=JINjELFfpTzYtnapT6oUzgAAAABOsTtM4LA1dhvIEf6FzaTE; incap_ses_170_2414945=Rca0c8Jx7zThR7YQcvZbAo8BCWgAAAAAKod7pvZxBtaaxwdn+IMBbg==; _ga=GA1.1.1103274445.1745420689; _ga_PLWWB73JH3=GS1.1.1745420689.1.1.1745420692.0.0.0; OptanonConsent=isIABGlobal=false&datestamp=Wed+Apr+23+2025+11%3A04%3A53+GMT-0400+(Eastern+Daylight+Time)&version=202209.2.0&hosts=&landingPath=https%3A%2F%2Fapp.idx.us%2Fen-US%2Flogin%2Fdata-center%252Fpersonal%3Fbrand%3D&groups=C0001%3A1%2CC0004%3A0%2CC0003%3A0%2CC0002%3A0
Source: global trafficHTTP traffic detected: GET /logos/static/ot_persistent_cookie.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /logos/static/ot_persistent_cookie.png HTTP/1.1Host: cdn.cookielaw.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: email.mg.idx.us
Source: global trafficDNS traffic detected: DNS query: app.idx.us
Source: global trafficDNS traffic detected: DNS query: use.fontawesome.com
Source: global trafficDNS traffic detected: DNS query: cdn.cookielaw.org
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: services.myidcare.com
Source: unknownHTTP traffic detected: POST /v1/auth/account/login HTTP/1.1Host: services.myidcare.comConnection: keep-aliveContent-Length: 51sec-ch-ua-platform: "Windows"Accept-Language: en-US,en;q=1Accept: application/json, text/plain, */*sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Content-Type: application/jsonsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Origin: https://app.idx.usSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://app.idx.us/Accept-Encoding: gzip, deflate, br, zstd
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50046 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50047 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50047
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50046
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50048
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49908
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 34.102.239.211:443 -> 192.168.2.18:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.102.239.211:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.27.152:443 -> 192.168.2.18:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.86.42:443 -> 192.168.2.18:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.18:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.86.42:443 -> 192.168.2.18:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.27.152:443 -> 192.168.2.18:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.87.42:443 -> 192.168.2.18:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49747 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49748 version: TLS 1.2
Source: unknownHTTPS traffic detected: 45.60.62.175:443 -> 192.168.2.18:49901 version: TLS 1.2
Source: classification engineClassification label: clean1.win@22/23@18/167
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,14289345589960235143,3705958016247783956,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2228 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2008,i,14289345589960235143,3705958016247783956,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2228 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Drive-by Compromise
Windows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Extra Window Memory Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://use.fontawesome.com/69007daa2f.css0%Avira URL Cloudsafe
https://app.idx.us/en-US/main.779297c0974f4c68.js0%Avira URL Cloudsafe
https://use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.css0%Avira URL Cloudsafe
https://app.idx.us/en-US/runtime.069f6ad593699107.js0%Avira URL Cloudsafe
https://app.idx.us/data-center/personal?brand=0%Avira URL Cloudsafe
https://app.idx.us/en-US/polyfills.b3873936e16841b7.js0%Avira URL Cloudsafe
https://use.fontawesome.com/69007daa2f.js0%Avira URL Cloudsafe
https://app.idx.us/en-US/hashes.47ba75654ba416c6.js0%Avira URL Cloudsafe
https://app.idx.us/en-US/assets/img/idx_glyph_2.0.png0%Avira URL Cloudsafe
https://app.idx.us/en-US/styles.1eee1ae52eb0e54a.css0%Avira URL Cloudsafe
https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/v2/otPcCenter.json0%Avira URL Cloudsafe
https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otCommonStyles.css0%Avira URL Cloudsafe
https://cdn.cookielaw.org/logos/static/poweredBy_ot_logo.svg0%Avira URL Cloudsafe
https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otCookieSettingsButton.json0%Avira URL Cloudsafe
https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otFloatingRoundedCorner.json0%Avira URL Cloudsafe
https://cdn.cookielaw.org/logos/static/ot_persistent_cookie.png0%Avira URL Cloudsafe
https://use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff20%Avira URL Cloudsafe
https://cdn.cookielaw.org/scripttemplates/202209.2.0/otBannerSdk.js0%Avira URL Cloudsafe
https://cdn.cookielaw.org/logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/2bbb96d4-2e44-4476-85a5-39074d56a5c4/349e79cb-92c6-48ea-8758-07d5f9e355d4/IDXlogo_100px.png0%Avira URL Cloudsafe
https://app.idx.us/en-US/English.c8533c11959a8c72.svg0%Avira URL Cloudsafe
https://app.idx.us/_Incapsula_Resource?SWKMTFSR=1&e=0.76481256227373940%Avira URL Cloudsafe
https://cdn.cookielaw.org/consent/e8b305c7-027f-445b-955e-48b356dac2ca/7f8bc42a-4403-43b5-80d3-6e860ef32e59/en.json0%Avira URL Cloudsafe
https://app.idx.us/en-US/favicon.ico?v=10%Avira URL Cloudsafe
https://cdn.cookielaw.org/consent/e8b305c7-027f-445b-955e-48b356dac2ca/e8b305c7-027f-445b-955e-48b356dac2ca.json0%Avira URL Cloudsafe
https://cdn.cookielaw.org/logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/e8b305c7-027f-445b-955e-48b356dac2ca/242c0063-9eef-4afd-9139-94f6cdc699c5/OneTrust_logoSize.png0%Avira URL Cloudsafe
https://app.idx.us/en-US/assets/img/idx_logo.png0%Avira URL Cloudsafe
https://app.idx.us/_Incapsula_Resource?SWJIYLWA=719d34d31c8e3a6e6fffd425f7e032f3&ns=1&cb=7846749850%Avira URL Cloudsafe
https://services.myidcare.com/v1/auth/account/login0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
aavtsdr.x.incapdns.net
45.60.62.175
truefalse
    unknown
    www.google.com
    142.250.69.4
    truefalse
      high
      use.fontawesome.com.cdn.cloudflare.net
      104.21.27.152
      truefalse
        high
        cdn.cookielaw.org
        104.18.86.42
        truefalse
          high
          mailgun.org
          34.102.239.211
          truefalse
            high
            services.myidcare.com
            45.60.62.175
            truefalse
              unknown
              app.idx.us
              unknown
              unknownfalse
                unknown
                use.fontawesome.com
                unknown
                unknownfalse
                  high
                  email.mg.idx.us
                  unknown
                  unknownfalse
                    unknown
                    NameMaliciousAntivirus DetectionReputation
                    https://app.idx.us/en-US/login/data-center%2Fpersonal?brand=false
                      unknown
                      https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otCommonStyles.cssfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otCookieSettingsButton.jsonfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://app.idx.us/data-center/personal?brand=false
                      • Avira URL Cloud: safe
                      unknown
                      https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYffalse
                        unknown
                        https://app.idx.us/en-US/hashes.47ba75654ba416c6.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://services.myidcare.com/v1/auth/account/loginfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/styles.1eee1ae52eb0e54a.cssfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/v2/otPcCenter.jsonfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otFloatingRoundedCorner.jsonfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/runtime.069f6ad593699107.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/logos/static/poweredBy_ot_logo.svgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/assets/img/idx_glyph_2.0.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://use.fontawesome.com/69007daa2f.cssfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://use.fontawesome.com/69007daa2f.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/polyfills.b3873936e16841b7.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff2false
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/main.779297c0974f4c68.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/logos/static/ot_persistent_cookie.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/scripttemplates/202209.2.0/otBannerSdk.jsfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/English.c8533c11959a8c72.svgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/2bbb96d4-2e44-4476-85a5-39074d56a5c4/349e79cb-92c6-48ea-8758-07d5f9e355d4/IDXlogo_100px.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/_Incapsula_Resource?SWJIYLWA=719d34d31c8e3a6e6fffd425f7e032f3&ns=1&cb=784674985false
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/_Incapsula_Resource?SWKMTFSR=1&e=0.7648125622737394false
                        • Avira URL Cloud: safe
                        unknown
                        https://app.idx.us/en-US/favicon.ico?v=1false
                        • Avira URL Cloud: safe
                        unknown
                        https://cdn.cookielaw.org/logos/static/ot_close.svgfalse
                          high
                          https://cdn.cookielaw.org/logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/e8b305c7-027f-445b-955e-48b356dac2ca/242c0063-9eef-4afd-9139-94f6cdc699c5/OneTrust_logoSize.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://cdn.cookielaw.org/consent/e8b305c7-027f-445b-955e-48b356dac2ca/7f8bc42a-4403-43b5-80d3-6e860ef32e59/en.jsonfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://cdn.cookielaw.org/consent/e8b305c7-027f-445b-955e-48b356dac2ca/e8b305c7-027f-445b-955e-48b356dac2ca.jsonfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://app.idx.us/en-US/assets/img/idx_logo.pngfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.cssfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://cdn.cookielaw.org/scripttemplates/otSDKStub.jsfalse
                            high
                            • No. of IPs < 25%
                            • 25% < No. of IPs < 50%
                            • 50% < No. of IPs < 75%
                            • 75% < No. of IPs
                            IPDomainCountryFlagASNASN NameMalicious
                            142.250.69.4
                            www.google.comUnited States
                            15169GOOGLEUSfalse
                            104.18.87.42
                            unknownUnited States
                            13335CLOUDFLARENETUSfalse
                            1.1.1.1
                            unknownAustralia
                            13335CLOUDFLARENETUSfalse
                            192.178.49.170
                            unknownUnited States
                            15169GOOGLEUSfalse
                            142.250.69.8
                            unknownUnited States
                            15169GOOGLEUSfalse
                            192.178.49.195
                            unknownUnited States
                            15169GOOGLEUSfalse
                            45.60.62.175
                            aavtsdr.x.incapdns.netUnited States
                            19551INCAPSULAUSfalse
                            192.178.49.174
                            unknownUnited States
                            15169GOOGLEUSfalse
                            192.178.49.163
                            unknownUnited States
                            15169GOOGLEUSfalse
                            192.178.49.202
                            unknownUnited States
                            15169GOOGLEUSfalse
                            142.250.68.238
                            unknownUnited States
                            15169GOOGLEUSfalse
                            142.250.69.14
                            unknownUnited States
                            15169GOOGLEUSfalse
                            104.21.27.152
                            use.fontawesome.com.cdn.cloudflare.netUnited States
                            13335CLOUDFLARENETUSfalse
                            142.250.101.84
                            unknownUnited States
                            15169GOOGLEUSfalse
                            34.102.239.211
                            mailgun.orgUnited States
                            15169GOOGLEUSfalse
                            104.18.86.42
                            cdn.cookielaw.orgUnited States
                            13335CLOUDFLARENETUSfalse
                            IP
                            192.168.2.18
                            Joe Sandbox version:42.0.0 Malachite
                            Analysis ID:1672187
                            Start date and time:2025-04-23 17:04:12 +02:00
                            Joe Sandbox product:CloudBasic
                            Overall analysis duration:
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                            Sample URL:https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf
                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                            Number of analysed new started processes analysed:14
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • EGA enabled
                            Analysis Mode:stream
                            Analysis stop reason:Timeout
                            Detection:CLEAN
                            Classification:clean1.win@22/23@18/167
                            • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                            • Excluded IPs from analysis (whitelisted): 192.178.49.174, 192.178.49.195, 142.250.101.84, 142.250.69.14, 142.250.69.8, 192.178.49.163, 192.178.49.202, 142.250.68.238, 184.29.183.29
                            • Excluded domains from analysis (whitelisted): fonts.googleapis.com, fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, www.googletagmanager.com, fonts.gstatic.com, clientservices.googleapis.com, clients.l.google.com, www.google-analytics.com
                            • Not all processes where analyzed, report is missing behavior information
                            • Report size getting too big, too many NtOpenFile calls found.
                            • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                            • VT rate limit hit for: https://email.mg.idx.us/c/eJwsyTFytSAQAODTQPc76y4KFhT_zItdDrHu8qITBQZJ5uX2aVJ_Gj2Nfgs2xdG7iWbnfbB7lDlsCiSQ_DZPwE5ZaEzgSWkKC9sjIuAEDhGJcApDkiAOQJZF-Sk0GgfXx3Doa_i67Rn33utt6L_B1eDKtf6RwVW58z9JuadmcK2p3SXzaWjdGmc19LAtXtx-hspZy_ksxoGylM77xvlzkHLZHt9LPnppSR_c-e1Vy53Ufkf8DQAA__-DKkYf
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):62174
                            Entropy (8bit):5.4113440416800325
                            Encrypted:false
                            SSDEEP:
                            MD5:DA2211668BFE4A408835AF32B2DFA993
                            SHA1:F51F90BC32CD46C705C2ADB997A159DA1D986A68
                            SHA-256:02AA8872F610A5B394F1D8FBC6ABE0211E97F3D8A1E9DFD53AED7012977F7F0A
                            SHA-512:CECC45AF3CF4891960B568D0FB46CF45AACE83E4B27D94E2429AE9F2DCE0A2B6AC8B10138421CD36FE6ADFA375DC60C5D2C5D40AA6BB568C3C4EB7283622DFED
                            Malicious:false
                            Reputation:unknown
                            Preview:. {. "name": "otPcCenter",. "html": "PGRpdiBpZD0ib25ldHJ1c3QtcGMtc2RrIiBjbGFzcz0ib3RQY0NlbnRlciBvdC1oaWRlIG90LWZhZGUtaW4iIGFyaWEtbW9kYWw9InRydWUiIHJvbGU9ImFsZXJ0ZGlhbG9nIiBhcmlhLWRlc2NyaWJlZGJ5PSJvdC1wYy1kZXNjIj48IS0tIENsb3NlIEJ1dHRvbiAtLT48ZGl2IGNsYXNzPSJvdC1wYy1oZWFkZXIiPjwhLS0gTG9nbyBUYWcgLS0+PGRpdiBjbGFzcz0ib3QtcGMtbG9nbyIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJDb21wYW55IExvZ28iPjwvZGl2PjxidXR0b24gaWQ9ImNsb3NlLXBjLWJ0bi1oYW5kbGVyIiBjbGFzcz0ib3QtY2xvc2UtaWNvbiIgYXJpYS1sYWJlbD0iQ2xvc2UiPjwvYnV0dG9uPjwvZGl2PjwhLS0gQ2xvc2UgQnV0dG9uIC0tPjxkaXYgaWQ9Im90LXBjLWNvbnRlbnQiIGNsYXNzPSJvdC1wYy1zY3JvbGxiYXIiPjxoMiBpZD0ib3QtcGMtdGl0bGUiPllvdXIgUHJpdmFjeTwvaDI+PGRpdiBpZD0ib3QtcGMtZGVzYyI+PC9kaXY+PGJ1dHRvbiBpZD0iYWNjZXB0LXJlY29tbWVuZGVkLWJ0bi1oYW5kbGVyIj5BbGxvdyBhbGw8L2J1dHRvbj48c2VjdGlvbiBjbGFzcz0ib3Qtc2RrLXJvdyBvdC1jYXQtZ3JwIj48aDMgaWQ9Im90LWNhdGVnb3J5LXRpdGxlIj5NYW5hZ2UgQ29va2llIFByZWZlcmVuY2VzPC9oMz48ZGl2IGNsYXNzPSJvdC1wbGktaGRyIj48c3BhbiBjbGFzcz0ib3QtbGktdGl0bGUiPkNvbnNlbn
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:JSON data
                            Category:downloaded
                            Size (bytes):10019
                            Entropy (8bit):5.3453559766842895
                            Encrypted:false
                            SSDEEP:
                            MD5:F2F6634BA3DD149165F39759CC7D63DA
                            SHA1:4EEC89B86C945BF1DF6E229AD5C80077372FCE76
                            SHA-256:CE26ECDF22DD9987049B1BDC32D7EBDFEB55B26BD607D83A13F31079BCD6E131
                            SHA-512:9BBC2366B0A6F01C10920F3A2A441BC64FCA379F132C38CA33A6F05A6D38F2FDD1EF74542370016CC6543857DEC3AA23A99224203A6B2F8C1E3C9D6F018CFB0D
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otFloatingRoundedCorner.json
                            Preview:. {. "name": "otFloatingRoundedCorner",. "html": "PGRpdiBpZD0ib25ldHJ1c3QtYmFubmVyLXNkayIgY2xhc3M9Im90RmxvYXRpbmdSb3VuZGVkQ29ybmVyIj48ZGl2IGNsYXNzPSJvdC1zZGstY29udGFpbmVyIiByb2xlPSJhbGVydGRpYWxvZyIgYXJpYS1kZXNjcmliZWRieT0ib25ldHJ1c3QtcG9saWN5LXRleHQiPjxkaXYgY2xhc3M9Im90LXNkay1yb3ciPjxkaXYgaWQ9Im9uZXRydXN0LWdyb3VwLWNvbnRhaW5lciIgY2xhc3M9Im90LXNkay10d2VsdmUgb3Qtc2RrLWNvbHVtbnMiPjxkaXYgaWQ9Im9uZXRydXN0LXBvbGljeSI+PGRpdiBjbGFzcz0iYmFubmVyLWhlYWRlciI+PGRpdiBjbGFzcz0iYmFubmVyX2xvZ28iPjwvZGl2PjwvZGl2PjxoMiBpZD0ib25ldHJ1c3QtcG9saWN5LXRpdGxlIj5UaGlzIHNpdGUgdXNlcyBjb29raWVzPC9oMj48cCBpZD0ib25ldHJ1c3QtcG9saWN5LXRleHQiPnRpdGxlPGEgaHJlZj0iIyI+cG9saWN5PC9hPjwvcD48ZGl2IGNsYXNzPSJvdC1kcGQtY29udGFpbmVyIj48aDMgY2xhc3M9Im90LWRwZC10aXRsZSI+PC9oMz48ZGl2IGNsYXNzPSJvdC1kcGQtY29udGVudCI+PHAgY2xhc3M9Im90LWRwZC1kZXNjIj48L3A+PC9kaXY+PC9kaXY+PC9kaXY+PGRpdiBpZD0iYmFubmVyLW9wdGlvbnMiPjxkaXYgY2xhc3M9ImJhbm5lci1vcHRpb24iPjxidXR0b24gY2xhc3M9ImJhbm5lci1vcHRpb24taW5wdXQiIGFyaWEtZ
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (6129)
                            Category:downloaded
                            Size (bytes):366910
                            Entropy (8bit):5.602419306063648
                            Encrypted:false
                            SSDEEP:
                            MD5:28C32C1AFC0FBE50DF0BDB32EF011F15
                            SHA1:3D17CDDFF93243980962DD3251AE81093797FA96
                            SHA-256:B2F68A5170F7BC809F33343D969387170840B46E7F92D15ED31B8406F5DD1285
                            SHA-512:45E0D14EF8ED4EFF68ACE41A24DF5C928508224C22EA4E040E502CB489944D7BD48610126E581168615ED03985A86E0D5459DC49498961860B79A530F660C240
                            Malicious:false
                            Reputation:unknown
                            URL:https://www.googletagmanager.com/gtag/js?id=G-PLWWB73JH3
                            Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":11,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (65451)
                            Category:downloaded
                            Size (bytes):389442
                            Entropy (8bit):5.355893242780212
                            Encrypted:false
                            SSDEEP:
                            MD5:BFC851DB5D0CBDCC4C71D9B26D6DE6BD
                            SHA1:E9ECEA68471B0B5848C337A23F3758147ED1A46B
                            SHA-256:2C75C4C4D0AED145958AFCEB33A11E5D84C41343C718F93B77DFE4F4A9B85046
                            SHA-512:934BC878422F5AED0DA95C960F728708591B9360E904AF3DF0D40B50700B8D3B40FA890BE4C17D42D4E61BE9434521211AF84C50BDE1703FC5CEBCFC7A5E91D0
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/scripttemplates/202209.2.0/otBannerSdk.js
                            Preview:/** . * onetrust-banner-sdk. * v202209.2.0. * by OneTrust LLC. * Copyright 2022 . */.!function(){"use strict";var o=function(e,t){return(o=Object.setPrototypeOf||{__proto__:[]}instanceof Array&&function(e,t){e.__proto__=t}||function(e,t){for(var o in t)t.hasOwnProperty(o)&&(e[o]=t[o])})(e,t)};var k,e,r=function(){return(r=Object.assign||function(e){for(var t,o=1,n=arguments.length;o<n;o++)for(var r in t=arguments[o])Object.prototype.hasOwnProperty.call(t,r)&&(e[r]=t[r]);return e}).apply(this,arguments)};function d(i,s,a,l){return new(a=a||Promise)(function(e,t){function o(e){try{r(l.next(e))}catch(e){t(e)}}function n(e){try{r(l.throw(e))}catch(e){t(e)}}function r(t){t.done?e(t.value):new a(function(e){e(t.value)}).then(o,n)}r((l=l.apply(i,s||[])).next())})}function g(o,n){var r,i,s,e,a={label:0,sent:function(){if(1&s[0])throw s[1];return s[1]},trys:[],ops:[]};return e={next:t(0),throw:t(1),return:t(2)},"function"==typeof Symbol&&(e[Symbol.iterator]=function(){return this}),e;function t
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:SVG Scalable Vector Graphics image
                            Category:dropped
                            Size (bytes):651
                            Entropy (8bit):4.3413895961447135
                            Encrypted:false
                            SSDEEP:
                            MD5:A5C5D6146A6E55E4A0FE3567602B1E46
                            SHA1:C75FF1B713378AEC779FB248E22DAA513ACA725B
                            SHA-256:901BB0E03B8C3C0A1CF4C487A177417328BB7D8C94106ECEFCEEDD7D7F6C4DDC
                            SHA-512:D21D979974542243A4D70036F87BFC0549B6793B809ED09044946BE2A25C47811A99E20FDB1F3044082A5509664101D4BCA241A1CA7B09FE80084CEAFA092368
                            Malicious:false
                            Reputation:unknown
                            Preview:<svg xmlns="http://www.w3.org/2000/svg" width="348.333" height="348.333" viewBox="0 0 348.333 348.334"><path fill="#565656" d="M336.559 68.611L231.016 174.165l105.543 105.549c15.699 15.705 15.699 41.145 0 56.85-7.844 7.844-18.128 11.769-28.407 11.769-10.296 0-20.581-3.919-28.419-11.769L174.167 231.003 68.609 336.563c-7.843 7.844-18.128 11.769-28.416 11.769-10.285 0-20.563-3.919-28.413-11.769-15.699-15.698-15.699-41.139 0-56.85l105.54-105.549L11.774 68.611c-15.699-15.699-15.699-41.145 0-56.844 15.696-15.687 41.127-15.687 56.829 0l105.563 105.554L279.721 11.767c15.705-15.687 41.139-15.687 56.832 0 15.705 15.699 15.705 41.145.006 56.844z"/></svg>
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with no line terminators
                            Category:downloaded
                            Size (bytes):96
                            Entropy (8bit):5.1864745487572925
                            Encrypted:false
                            SSDEEP:
                            MD5:0A1DC8C8B54B6801851075BFDA51D54F
                            SHA1:1C4877B5684009681747DEDA4503D41E47082955
                            SHA-256:18FAB7216C79613E126E2FC708E4A30987AB65949AA69937D75907C295AD7D9A
                            SHA-512:39501AB5524003672A1A2F36C9B16721A4F830DE33D84CA651B3AF2180058A0A8E1EEF104B2887810F21A09BB2A1C7F3CA4B62E7D1CD560B0376845AFDD6E94D
                            Malicious:false
                            Reputation:unknown
                            URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIgCS2d0Hy36NKGEgUNFReaERIFDQiJrbYhlvfhkq5VcV0=?alt=proto
                            Preview:CkQKEQ0VF5oRGgQICRgBGgQIVhgCCi8NCImtthoECEsYAioiCApSHgoUIUAkIy4qLT8lJi8rX14pPSg6LFwQARj/////Dw==
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
                            Category:downloaded
                            Size (bytes):77160
                            Entropy (8bit):7.996509451516447
                            Encrypted:true
                            SSDEEP:
                            MD5:AF7AE505A9EED503F8B8E6982036873E
                            SHA1:D6F48CBA7D076FB6F2FD6BA993A75B9DC1ECBF0C
                            SHA-256:2ADEFCBC041E7D18FCF2D417879DC5A09997AA64D675B7A3C4B6CE33DA13F3FE
                            SHA-512:838FEFDBC14901F41EDF995A78FDAC55764CD4912CCB734B8BEA4909194582904D8F2AFDF2B6C428667912CE4D65681A1044D045D1BC6DE2B14113F0315FC892
                            Malicious:false
                            Reputation:unknown
                            URL:https://use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff2
                            Preview:wOF2......-h..........-.........................?FFTM.. .`..r.....(..X.6.$..p..... .....u[R.rGa...*...'.=.:..&..=r.*.......].t..E.n.......1F...@....|....f.m.`.$..@d[BQ.$([U<+(..@P.5..`....>.P..;.(..1..l..h...)..Yy..Ji......|%..^..G..3..n........D..p\Yr .L.P.....t.)......6R.^"S.L~.YR.CXR...4...F.y\[..7n..|.s.q..M..%K......,.....L.t.'....M.,..c..+b....O.s.^.$...z...m...h&gb...v.....'..6.:....s.m.b.1.m0"....*V.....c.$,0ATPT.1.....<..;...`..'.H.?.s.:..ND.....I..$..T..[..b4........,....bl6...IL.i}.&.4.m,'....#....Rw..bu..,K......v....m_-...\H....HH.......?...m..9P...)9.J..$.....8......~.;.r..n.=$.....Nddn.!'....;...8..'.N...!.-..J.........X.=.,......"`:....... {......K!'...-FH....#$~.Z_.......N5VU8F....%.P..........Cp..$.Q.......r.....k.k...3...:R.%....2{.....h%.)8..........ILK.6v.#......,;.6..N.2.hv...........OO..t#....xT..Bf....q^.#....?{.5b.I..%-WZ..b.A...^.1..n5.....NQ.Y'.........S.....!t" .`b3..%....35....fv;....l..9.:jgf?gr..p.x. ..|.. $. e.
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:PNG image data, 85 x 71, 8-bit/color RGBA, non-interlaced
                            Category:dropped
                            Size (bytes):3288
                            Entropy (8bit):7.885896546015819
                            Encrypted:false
                            SSDEEP:
                            MD5:07B4A05227BA9E0B0999AAFD17ACF5A0
                            SHA1:8C318A67AA5B88C931D54B401CF6B0FBEE48E386
                            SHA-256:B090476FD84B16DD8BC6C2797E324DE3341590E49C817A50E7B6B7BE58C2F4A5
                            SHA-512:7B2097D1AC91E3E4F0D585B3CDB35C0A0FCF693FB240BCDF7B5ECFD89DBCDBDA723E5F6878C0713016329AADEE31C80497A253377C65A6DB663C26E95681DC2B
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR...U...G.....v.......sRGB........DeXIfMM.*.......i.......................................U...........G.......Q...BIDATx..ytT....}3....Q..'3.Zz.`,....$...(.X.....Y.h...c]..f&Bq.J.T... ..-Z.,J...j.*.HB ...~.o...d..X.?.}...}y..{....f.S."..(..."..(..."..(..."..(..."..(...".......n%._u.......th.L.y....D}U.@...^...pX..........&...*^.8...O@._.....4....]a..~..K.......Uy ..P.e<u.q.[....?....Dd.4.g1.kp......./.zp..6..|..t+D.H....]_..........e..8oD..=].o.`..K.3&.......2.WuU.)U.....+....$.#.l.}s....u^E...r.Y...&..{.B8.@.jv.._}d.....6>.R...8.\./..g.6.Hm-..~..-d\..........v..M..:O=.p.`c..*a!..}..".s.g/..f.,.Zs..|.9\.-...._.:.|#..7..k5|t9.........<X:qb..@ ..}..3..t..u......YN6.p...s.+.G".P{{.CY6.qI.\|....+>p.%GN.3q!6....%...;...8.&hu..u...Q..G..+.......VS...<...E..7........a.=.m.#......sD"..b....M{>{.....py...y@.....s.O.l\|r..........A..3..=%}.B..?,.Y....T...e..Y.&.Q..#..Ur|*)m...w..:.o..o_m.k....>s....`..B..<...v.....}..k|...:.Y..l....i..L...
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:JSON data
                            Category:downloaded
                            Size (bytes):4706
                            Entropy (8bit):5.664238418373257
                            Encrypted:false
                            SSDEEP:
                            MD5:DC3B7174D8C152944B7A4367D58011EC
                            SHA1:1403ECC202C8C2DF0CC03A7D366B04F278DCD9CA
                            SHA-256:A09D0F89E99CF5A081315FF701187632005DABD23F3CA116A75790003FAA7E8F
                            SHA-512:1296E4352EBEB95ECC5B6EF3FD1398BD2A18D709E16EAB51735247EDA9EB3941433003C0072E2FCCADFB092D17BEC27C280C346EA9D8DAC6490AB205D2AF04B0
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/scripttemplates/202209.2.0/assets/otCookieSettingsButton.json
                            Preview:. {. "name": "otCookieSettingsButton",. "html": "PGRpdiBpZD0ib3Qtc2RrLWJ0bi1mbG9hdGluZyIgdGl0bGU9Ik1hbmFnZSBQcml2YWN5IFByZWZlcmVuY2VzIiBjbGFzcz0ib3QtZmxvYXRpbmctYnV0dG9uIG90LWhpZGUiPjxkaXYgY2xhc3M9Im90LWZsb2F0aW5nLWJ1dHRvbl9fZnJvbnQiPjxidXR0b24gdHlwZT0iYnV0dG9uIiBjbGFzcz0ib3QtZmxvYXRpbmctYnV0dG9uX19vcGVuIj48L2J1dHRvbj48L2Rpdj48ZGl2IGNsYXNzPSJvdC1mbG9hdGluZy1idXR0b25fX2JhY2siPjxidXR0b24gdHlwZT0iYnV0dG9uIiBjbGFzcz0ib3QtZmxvYXRpbmctYnV0dG9uX19jbG9zZSI+PCEtLT94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPy0tPiA8c3ZnIHJvbGU9InByZXNlbnRhdGlvbiIgdmlld0JveD0iMCAwIDI0IDI0IiB2ZXJzaW9uPSIxLjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+PGcgaWQ9IlBhZ2UtMSIgc3Ryb2tlPSJub25lIiBzdHJva2Utd2lkdGg9IjEiIGZpbGw9Im5vbmUiIGZpbGwtcnVsZT0iZXZlbm9kZCI+PGcgaWQ9IkJhbm5lcl8wMiIgY2xhc3M9Im90LWZsb2F0aW5nLWJ1dHRvbl9fc3ZnLWZpbGwiIHRyYW5zZm9ybT0idHJhbnNsYXRlKC0zMTguMDAwMDAwLCAtNzI1LjAwMDAwMCkiIGZpbGw9IiNmZmZmZmYiIGZpbGwtcnVsZT0ibm9uemVybyI+PGcgaWQ9Ikdyb3VwLTIiIHRyYW5zZm9ybT
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text
                            Category:downloaded
                            Size (bytes):1033
                            Entropy (8bit):4.900634549051502
                            Encrypted:false
                            SSDEEP:
                            MD5:C1EF8AB7C4CA4930FA553116B6C78612
                            SHA1:B1FE3C6E345F53197FBE0224F213738F2A044C0E
                            SHA-256:EDDF3E47FD0CD955700288C3843D732F11736D42AF552DA69C3D5F1FE24525B2
                            SHA-512:EC1E36834810BA8B1ACC5E51F43DA95563F1D51879C7D3B4B7D9FDE4842FB088A3B15639562C1D5C6C496B92A6F49FD4A8EF6104DA6E9CFB772D109ED5A46963
                            Malicious:false
                            Reputation:unknown
                            URL:https://use.fontawesome.com/69007daa2f.css
                            Preview:/*!. * Font Awesome v4.7.0 by @davegandy - http://fontawesome.io - @fontawesome. * License - http://fontawesome.io/license (Font: SIL OFL 1.1, CSS: MIT License). */.@import url('//use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.css');./* FONT PATH. * -------------------------- */.@font-face {. font-family: 'FontAwesome';. src: url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.eot');. src: url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.eot?#iefix') format('embedded-opentype'),. url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff2') format('woff2'),. url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff') format('woff'),. url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.ttf') format('truetype'),. url('//use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.svg#fontawesomeregular') format('svg');. font-weight: normal;. font-style: norma
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (23566)
                            Category:downloaded
                            Size (bytes):23567
                            Entropy (8bit):5.380841760374884
                            Encrypted:false
                            SSDEEP:
                            MD5:047640006D5AB098020A6BF30FF5AEE9
                            SHA1:10D247BFD01CC8241BAFDF504D1160D456AEE901
                            SHA-256:A011BE10E83B3E4FF8BC831755B28089BAB9B64FC01DA437B3782B640B0B4689
                            SHA-512:DBAB3278895B7D31A8A2FF8C27CF840F7F20C9ECBF067242D950D3E67945DCA4E045B156401C4FFDE59BBD78DC742075B170227568C989DD6FD0B92F6FC3BCE2
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
                            Preview:var OneTrustStub=(t=>{var e,a,o,r,i,l=new function(){this.optanonCookieName="OptanonConsent",this.optanonHtmlGroupData=[],this.optanonHostData=[],this.genVendorsData=[],this.vendorsServiceData=[],this.IABCookieValue="",this.oneTrustIABCookieName="eupubconsent",this.oneTrustIsIABCrossConsentEnableParam="isIABGlobal",this.isStubReady=!0,this.geolocationCookiesParam="geolocation",this.EUCOUNTRIES=["BE","BG","CZ","DK","DE","EE","IE","GR","ES","FR","IT","CY","LV","LT","LU","HU","MT","NL","AT","PL","PT","RO","SI","SK","FI","SE","GB","HR","LI","NO","IS"],this.stubFileName="otSDKStub",this.DATAFILEATTRIBUTE="data-domain-script",this.bannerScriptName="otBannerSdk.js",this.domPurifyScriptName="otDomPurify.js",this.mobileOnlineURL=[],this.isMigratedURL=!1,this.migratedCCTID="[[OldCCTID]]",this.migratedDomainId="[[NewDomainId]]",this.userLocation={country:"",state:"",stateName:""}},s=((A=e=e||{})[A.Days=1]="Days",A[A.Weeks=7]="Weeks",A[A.Months=30]="Months",A[A.Years=365]="Years",(A=i=i||{}).GDPR=
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3306
                            Entropy (8bit):4.8535240307677725
                            Encrypted:false
                            SSDEEP:
                            MD5:0F4754F6273CA52F6CEC1985D5BBF0E8
                            SHA1:69358C2A3C93C666B81FF653830442D3AA6F8445
                            SHA-256:30922A249027CD885FF604A0161008BBC8328F1A3FC91AAC310186C78FDC8FB3
                            SHA-512:B4BE89ADA07598C2B91BE000935FF2543C883D5C7E776AD8445C3DF3B4A44117FD90D48379E40E6B05462418001DEF36DAACC743B5CBC5A56309B96196F112DB
                            Malicious:false
                            Reputation:unknown
                            Preview:{"CookieSPAEnabled":false,"CookieSameSiteNoneEnabled":false,"CookieV2CSPEnabled":false,"MultiVariantTestingEnabled":false,"UseV2":true,"MobileSDK":false,"SkipGeolocation":true,"ScriptType":"PRODUCTION","Version":"202209.2.0","OptanonDataJSON":"e8b305c7-027f-445b-955e-48b356dac2ca","GeolocationUrl":"https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location","BulkDomainCheckUrl":"https://cookies-data.onetrust.io/bannersdk/v1/domaingroupcheck","RuleSet":[{"Id":"7f8bc42a-4403-43b5-80d3-6e860ef32e59","Name":"Global","Countries":["pr","ps","pw","py","qa","ad","ae","af","ag","ai","al","am","ao","aq","ar","as","au","aw","az","ba","bb","rs","bd","ru","bf","rw","bh","bi","bj","bl","bm","bn","bo","sa","sb","bq","br","sc","sd","bs","bt","sg","bv","sh","bw","sj","by","bz","sl","sn","so","ca","sr","cc","ss","st","cd","cf","sv","cg","ch","sx","ci","sy","sz","ck","cl","cm","cn","co","cr","tc","td","tf","cu","tg","cv","cw","th","cx","tj","tk","tl","tm","tn","to","tr","tt","tv","tw","dj","tz","d
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:SVG Scalable Vector Graphics image
                            Category:dropped
                            Size (bytes):2998
                            Entropy (8bit):4.189711652602748
                            Encrypted:false
                            SSDEEP:
                            MD5:2E9B9AC8BE368C1EFCC51965C74BE43B
                            SHA1:DDE87F63ECBAEB97C5708CED6FFD0E7DE5A806C0
                            SHA-256:49B9B4996D1FF0A8E3DE643A0C623255BF631F298F2799B949C29DE93926EE7A
                            SHA-512:FFC56944E751D82233F3ED504EB42A44544CB4E58969E8AC3ABD76D96C0607282FEE0E52F13AED8902B05330E0C82E74BA8592FF2BDCBF0188BE8898EFB2C741
                            Malicious:false
                            Reputation:unknown
                            Preview:<svg width="136" height="16" xmlns="http://www.w3.org/2000/svg"><g fill="none"><path d="M79.039 7.346c0 1.784-.449 3.186-1.346 4.206-.897 1.021-2.152 1.532-3.767 1.532-1.641 0-2.905-.505-3.791-1.513-.887-1.008-1.335-2.422-1.346-4.24 0-1.815.449-3.221 1.346-4.22.897-1 2.165-1.498 3.805-1.496 1.6 0 2.85.507 3.748 1.523.899 1.015 1.35 2.418 1.351 4.208zm-8.88 0c0 1.51.32 2.654.963 3.434.642.78 1.577 1.17 2.804 1.168 1.234 0 2.166-.388 2.796-1.165.63-.777.945-1.923.947-3.437 0-1.498-.314-2.634-.942-3.41-.627-.774-1.557-1.163-2.787-1.164-1.235 0-2.173.39-2.815 1.17-.642.78-.964 1.915-.964 3.404h-.002zm16.891 5.587V7.535c0-.68-.155-1.188-.466-1.523-.31-.336-.795-.504-1.455-.504-.874 0-1.514.236-1.922.708-.407.472-.61 1.251-.61 2.339v4.378h-1.265V4.575h1.028l.204 1.143h.062a2.583 2.583 0 011.076-.955 3.541 3.541 0 011.564-.339c1.006 0 1.763.242 2.271.727.508.484.762 1.26.762 2.327v5.455H87.05zm7.392.151c-1.234 0-2.208-.376-2.922-1.128-.714-.752-1.073-1.796-1.077-3.132 0-1.346.332-2.415.996-3.
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (30343)
                            Category:downloaded
                            Size (bytes):30344
                            Entropy (8bit):4.71081887626325
                            Encrypted:false
                            SSDEEP:
                            MD5:36082410DF2EF7F83932219089DC1443
                            SHA1:7961402D7D01E19387FE609A38454B0BC8C6CCA4
                            SHA-256:5B9573E1023DA775390E9284EC0EB1C606DF9B468A28980055B4A6AA804F4350
                            SHA-512:806FF5B14991E42523541D89A18EB295C4BC3DD7C7E9895068EF083A898DBE928D3852638CF106D0A646617E773CA2084B439659B41B3125B7E4FCA1D2D81FB1
                            Malicious:false
                            Reputation:unknown
                            URL:https://use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.css
                            Preview:.fa{display:inline-block;font:normal normal normal 14px/1 FontAwesome;font-size:inherit;text-rendering:auto;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.fa-lg{font-size:1.33333333em;line-height:.75em;vertical-align:-15%}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-fw{width:1.28571429em;text-align:center}.fa-ul{padding-left:0;margin-left:2.14285714em;list-style-type:none}.fa-ul>li{position:relative}.fa-li{position:absolute;left:-2.14285714em;width:2.14285714em;top:.14285714em;text-align:center}.fa-li.fa-lg{left:-1.85714286em}.fa-border{padding:.2em .25em .15em;border:solid .08em #eee;border-radius:.1em}.fa-pull-left{float:left}.fa-pull-right{float:right}.fa.fa-pull-left{margin-right:.3em}.fa.fa-pull-right{margin-left:.3em}.pull-right{float:right}.pull-left{float:left}.fa.pull-left{margin-right:.3em}.fa.pull-right{margin-left:.3em}.fa-spin{-webkit-animation:fa-spin 2s infinite linear;animation:fa-spin 2s infinite linear}
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:JSON data
                            Category:downloaded
                            Size (bytes):48603
                            Entropy (8bit):5.016297863817929
                            Encrypted:false
                            SSDEEP:
                            MD5:718AFFFEE5251CFFD383FF4880A11475
                            SHA1:1187C48B80FA752DB8530208E66D5B99653D3877
                            SHA-256:D4AE8653CA225B52C2DB1311D1E365FA4093F7917D4FE4E70988E21132A37EE8
                            SHA-512:AFC179F84FB268DAC768140FCB9E70275D215738B390EB51AD3859AC0995D7DFDC6055037FECA9B12E75854AA3785C964EA7156D736BDEA4C791390421570E3B
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/consent/e8b305c7-027f-445b-955e-48b356dac2ca/7f8bc42a-4403-43b5-80d3-6e860ef32e59/en.json
                            Preview:{"DomainData":{"pclifeSpanYrs":"Years","pclifeSpanSecs":"A few seconds","pclifeSpanWk":"Week","pclifeSpanWks":"Weeks","pccloseButtonType":"Icon","pccontinueWithoutAcceptText":"Continue without Accepting","pclifeSpanYr":"Year","cctId":"e8b305c7-027f-445b-955e-48b356dac2ca","MainText":"Privacy Preference Center","MainInfoText":"When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.","AboutText":"
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:PNG image data, 100 x 41, 8-bit/color RGBA, non-interlaced
                            Category:downloaded
                            Size (bytes):3898
                            Entropy (8bit):7.918475434334698
                            Encrypted:false
                            SSDEEP:
                            MD5:229F70EC09594BAC6BD6CE3C1B5D76D2
                            SHA1:E53BA194E6157F9FB1E205D0E72F19DD47312304
                            SHA-256:88FD1BCF07F918AD9A40CAA7EDE234D4CB50CBF087C9E422CE0CF502257881F8
                            SHA-512:81EC911A6D5CCDC33E5D676333AA2E60E2D10E8AE47236742DF7F399CEE1717889F462221F498D8B780BE3E5DE0A7239F450B7D73826BF2176EE4C4958927FAC
                            Malicious:false
                            Reputation:unknown
                            URL:https://cdn.cookielaw.org/logos/6cc62559-8f2c-4d7e-a7dc-d7cd55206a88/2bbb96d4-2e44-4476-85a5-39074d56a5c4/349e79cb-92c6-48ea-8758-07d5f9e355d4/IDXlogo_100px.png
                            Preview:.PNG........IHDR...d...)......$......sRGB........DeXIfMM.*.......i.......................................d...........)......B.....IDATx..[{tT....{w.AD.AP..]..HBB.Rm6.]...R.i..zT.yP_......j6..jQ.....!......@.@IH.....I6{..7ww6w_!.)....23...7s.7.=...Dy.+...J..+...0F...0|.;..(.q. ....^Y.C..f..Byt.0.X.m.m.B...`.....Vp0....Jy.D.(..BX..z....87.O.2X+.rB..z..n..P.arcn..>PFu....{0]..l2&...wp.&....!'d....R......b...n...&...-...tM..H..x9x+....%]0MN.^..j.f1.N{..*.frPpR&.......?^......U.1....~.0.vw.wF...b....$..h...I.P<._.V...xy.+...'9%_..#..9(.y..5...P..E...j..?F....U\Y[.......[......).....QP...$[..c..O|.{Z...1......l.7G.c.}.......?^.|.4..U.7o;.7X].Y..4wa3..V,.....^...,.(.M..O..P@)9..5Ae.;.v..../...Z..,{..g.|..M.E...>..........4wg~.gB&.Y..c...m$.\...b.fO...LK..kj.j..J3.F...t=-V...I.tHUM{[[7..&..b.....y...0..^..:,..`.Z..(.dB.4..>.m}...../5"#S.L^o...'.4...5@;OU.+.."U../.7..|.....;.lsV.....TK.ef....V.......a2.u....Q|.-L..`N.n..l.2\.Q#.......9..}ms0.[r.D}O..W`Ub...i
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (11231)
                            Category:dropped
                            Size (bytes):21083
                            Entropy (8bit):4.782590239065309
                            Encrypted:false
                            SSDEEP:
                            MD5:A10B26C2E2252561F870A0F1A48D65B4
                            SHA1:04ECB4436F819FF6C8635787FF6E02BCF23AE3B1
                            SHA-256:087D847EE64707E372F572145600ECBCB13F2DD2382FD8962326F2FED03DD85D
                            SHA-512:D05D6D49C10E2274523820E91E333CE01CAA8571A8E73315B96183A5B92A61E18D6036BDCA6F2FBC6C71C427728A3390830D0880F04365F78D14E9F31FBBE895
                            Malicious:false
                            Reputation:unknown
                            Preview:#onetrust-banner-sdk{-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}#onetrust-banner-sdk .onetrust-vendors-list-handler{cursor:pointer;color:#1f96db;font-size:inherit;font-weight:bold;text-decoration:none;margin-left:5px}#onetrust-banner-sdk .onetrust-vendors-list-handler:hover{color:#1f96db}#onetrust-banner-sdk:focus{outline:2px solid #000;outline-offset:-2px}#onetrust-banner-sdk a:focus{outline:2px solid #000}#onetrust-banner-sdk #onetrust-accept-btn-handler,#onetrust-banner-sdk #onetrust-reject-all-handler,#onetrust-banner-sdk #onetrust-pc-btn-handler{outline-offset:1px}#onetrust-banner-sdk.ot-bnr-w-logo .ot-bnr-logo{height:64px;width:64px}#onetrust-banner-sdk .ot-close-icon,#onetrust-pc-sdk .ot-close-icon,#ot-sync-ntfy .ot-close-icon{background-size:contain;background-repeat:no-repeat;background-position:center;height:12px;width:12px}#onetrust-banner-sdk .powered-by-logo,#onetrust-banner-sdk .ot-pc-footer-logo a,#onetrust-pc-sdk .powered-by-logo,#onetrust-pc-sdk .ot-pc-foo
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:Web Open Font Format (Version 2), TrueType, length 40128, version 1.0
                            Category:downloaded
                            Size (bytes):40128
                            Entropy (8bit):7.994526034157349
                            Encrypted:true
                            SSDEEP:
                            MD5:9A01B69183A9604AB3A439E388B30501
                            SHA1:8ED1D59003D0DBE6360481017B44665153665FBE
                            SHA-256:20B535FA80C8189E3B87D1803038389960203A886D502BC2EF1857AFFC2F38D2
                            SHA-512:0E6795255B6EEA00B5403FD7E3B904D52776D49AC63A31C2778361262883697943AEDCB29FEEE85694BA6F19EAA34DDDB9A5BFE7118F4A25B4757E92C331FECA
                            Malicious:false
                            Reputation:unknown
                            URL:https://fonts.gstatic.com/s/roboto/v47/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3yUBA.woff2
                            Preview:wOF2..............$....F..........................p.....t?HVAR...`?STAT.N'...B..~.../~.....`..i..X.0..j.6.$..,. .... ..N[{.q.v...Lw.Q..o..J...6.Z.g.F.n..g\{t....%.!3)....sS.o...$."c.^<.iZc.I]c....0+. ..I..9.H.3..B.&.....'e....5.p.R(.j~\=..Wt.{..1.[u..Fn..<.-g.3..L..o.....E.-Q.........I..-/.4....{.Uj...3.K...g.Z....0...2)%.{......gN.../f.7....o.K....^V...!j...<...gf....\XjI.<p.PJh.4....*,*.S....&.C...R..,@ba..<..z.|.X.&.(.mf.w[..l.35Mp...A.A.=d........fj...}W6..y....[...i.......!........NLND....n'"...N*k)0<n.P.......w.j..>9.vV...Z.`.$$!.".(.`ATV.,..0.]3.<.d(...-s...2.w....P@.&...-.9x7.'....Sg.N=m.=....(..))-bA<.x.......=@4qs..Ss......K...{.=H.......z...NUS....Y..6.K.......n.....F4.B....=w.....+..F3...fB..........y1...,.(...`,..&vIrP.^.fiQY..5....H.a......q...s."..\..':.xK}...fU.z.j.......$L.......f.g&....R...!.Wmew3.1%2W.'"6u..r.q"F.......~i{..9xN.g.X..NMx.H.s@.8..J.t.SP.C`-GU)G/'..6".+......f..n..Aw....r....l.<r...Cke..D....T/."..c..mj..
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:Web Open Font Format (Version 2), TrueType, length 128352, version 1.0
                            Category:downloaded
                            Size (bytes):128352
                            Entropy (8bit):7.998349465466699
                            Encrypted:true
                            SSDEEP:
                            MD5:53436ACA8627A49F4DEAAA44DC9E3C05
                            SHA1:0BC0C675480D94EC7E8609DDA6227F88C5D08D2C
                            SHA-256:8265F64786397D6B832D1CA0AAFDF149AD84E72759FFFA9F7272E91A0FB015D1
                            SHA-512:6655E0426EB0C78A7CB4D4216A3AF7A6EDD50ABA8C92316608B1F79B8FC15F895CBA9314BEB7A35400228786E2A78A33E8C03322DA04E0DA94C2F109241547E8
                            Malicious:false
                            Reputation:unknown
                            URL:https://fonts.gstatic.com/s/materialicons/v143/flUhRq6tzZclQEJ-Vdg-IuiaDsNc.woff2
                            Preview:wOF2.......`......~....................................D.`..........,..t..X..6.$..p. ..z. [.\.M.B.....-..VT .&"..Qc.=.U..XwD...7Q.v.a.*.; (...I........+.I..%...._.v.:..N.Y....;J.V...+..S..9Z...X.J........_0)c`[vb?.".P.E..Q......."p.v..........3.Zm`k":8..Kk........UR%U2...<....'a.L.4.&....P.X...,z5.j<++....ff..X1I.......%.Z<.UT.G.)L........;.A....O~ev...-z....^.|.....pE..@.t.7...4..>...}.U[y...O8....|m.L04....t...g...../...&.E...."...q.1.(..g.&?;...Vx..|.-p=......;...a..Q|*L8..}..$.*I*.2.tI8...O..Q...k+;..N.hf.M...t..(..\...O.......:n.... v..}H...|B<..'..r...1..B, .....6.&...6.x.i.=...r......Os.._...g.{W$VD..A1........B[.<un...t......k..n0........ ..O&.....%.@..c..Tv...pT.Np...U...%j+ZP....@.....b..........~...f..D..... ...O$....|......$W842...S.....2.pIL.....Z.[.xo.r.{.d)I.P.-)0..K.`.~,.8..[...m..3d....A..v.s.d..KW..j.4.Ic.m..,.P........../W.j...>B..BJ.........[?.....$."...-...K.P.R..K.....Dz(..7_...=.....b.C...2..4F.+....P...f.#.q.G.G8.
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:Unicode text, UTF-8 text, with very long lines (9239)
                            Category:downloaded
                            Size (bytes):9496
                            Entropy (8bit):5.287228266941021
                            Encrypted:false
                            SSDEEP:
                            MD5:015703C7186CD9D19E4C2E1CDA343C1B
                            SHA1:25AFE0C543DC98555E60885F50E36285C12AD46C
                            SHA-256:BD127CFB0C10900BE7233B61AA8CC4182A418EE41E5C7F4CE12EB55400D1D099
                            SHA-512:D18E13C8B938062B1ACC5461519BD0259AAC10D977B4902A330FE8A26A8BA5E13EB8C3F0A3B3331DEA68C233698309688EFF8858178F4E591957B0F10449E410
                            Malicious:false
                            Reputation:unknown
                            URL:https://use.fontawesome.com/69007daa2f.js
                            Preview:window.FontAwesomeCdnConfig = {. autoA11y: {. enabled: false. },. asyncLoading: {. enabled: false. },. reporting: {. enabled: false. },. useUrl: "use.fontawesome.com",. faCdnUrl: "https://cdn.fontawesome.com:443",. code: "69007daa2f".};.!function(){function a(a){var b,c=[],d=document,e=d.documentElement.doScroll,f="DOMContentLoaded",g=(e?/^loaded|^c/:/^loaded|^i|^c/).test(d.readyState);g||d.addEventListener(f,b=function(){for(d.removeEventListener(f,b),g=1;b=c.shift();)b()}),g?setTimeout(a,0):c.push(a)}function b(a,b){var c=!1;return a.split(",").forEach(function(a){var d=new RegExp(a.trim().replace(".","\\.").replace("*","(.*)"));b.match(d)&&(c=!0)}),c}function c(a){"undefined"!=typeof MutationObserver&&new MutationObserver(a).observe(document,{childList:!0,subtree:!0})}function d(a){var b,c,d,e;a=a||"fa",b=document.querySelectorAll("."+a),Array.prototype.forEach.call(b,function(a){c=a.getAttribute("title"),a.setAttribute("aria-hidden","true"),d=a.nextElementSibling?
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
                            Category:dropped
                            Size (bytes):4986
                            Entropy (8bit):7.950740496230034
                            Encrypted:false
                            SSDEEP:
                            MD5:421CC51C1034B6D086EAF588CD9CB20A
                            SHA1:DADD6101EE57F9D2B2037400584E41F3E2F4ECCF
                            SHA-256:AEC62B0FEBFEB8AA0BD77084687B92A2EC478764676764BBE7AF2FBB677AC883
                            SHA-512:A9775981EB5559084C2485CF8B969699444AAAAB78974A8271A2A5B94C4B7C2A7B7928C4EE8CCA007F56DE7AB4FF59D018F54331C9E483D8D02FFC88CF99924A
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR...d...d.....p.T....bKGD............./IDATx...wT....9....Q.Z.jm..?.=.K{.S....Z.V\..+.!....(...XQYd....BH ....d..r.|......;.....s..e...>..y..<..e.-...;.F.}".R.D.R.N..:..%.w>....>..E'G...@...T.j+...>..B.|..L...p..V.G..P...:..#t...To......Xa.;....mkJ........wY.V.i=../.}..Q..............+.X#t....q..X!....jm..`}..].M...{..#.{._e=..^kV.....j+..t..M......M....>..f..\j.^:(R.....\+.|.. .n.{...IB..H.8C.e......^.....r.d...^..U....F..^..Z...t.G....m&$....V".c....)..............^.).....B...3...4g.m;bM.:.`..&Vs].A7S....8......wvuX....\z}.2C...R._GW..1o...o.8..O...^X._.3.M#..o...w3..sN>.n..C+..r.1C.CK.l.?...*L..f..B.ta9.........Y...7.X6.....b.B......^+y.O0..........\.kf.B.^.As{SA....+M..7S...3.1.T}.a.5....4t...yo.}Y.....g*.c...0.w....-(!..l1.vx.....s...4...*~.SVe.O....5.+.>p..T..hp}.!.].Mt8.=.....QQ3.:...i.....O*'Y..v...j.....[.Z|a.....&......d.!...=.0..{.wvu.D....-NRi....S6..l..{..e.)f.pH6r.O..Mn~.b..H.ncje..?_..< .....>
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with no line terminators
                            Category:downloaded
                            Size (bytes):108
                            Entropy (8bit):5.242162883021849
                            Encrypted:false
                            SSDEEP:
                            MD5:508E6DD10542B4E6A7A407FC67294597
                            SHA1:F16AF4CFC09B28257D12C3398BD700E75746F406
                            SHA-256:D52E9AC109F8D6E46448EDB4387DFC8F9054B67EB8A263558475869261D7B5A0
                            SHA-512:9650F967F31BD7C9DBFBE3F6776AC78428D2F45A491B61D92096754FC4B790B329FAC7D1F8A61FFDF54DD79EB0C31ACA0B03C95E984731EDDF58245BF2D15D6B
                            Malicious:false
                            Reputation:unknown
                            URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIgCS2d0Hy36NKGEgUNFReaERIFDQiJrbYhlvfhkq5VcV0SGQnWkOXHBlwu9xIFDaWTNiQhD1p0CFiYpag=?alt=proto
                            Preview:CkQKEQ0VF5oRGgQICRgBGgQIVhgCCi8NCImtthoECEsYAioiCApSHgoUIUAkIy4qLT8lJi8rX14pPSg6LFwQARj/////DwoJCgcNpZM2JBoA
                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                            File Type:ASCII text, with very long lines (1572)
                            Category:downloaded
                            Size (bytes):32502
                            Entropy (8bit):5.274847756989502
                            Encrypted:false
                            SSDEEP:
                            MD5:9152012CD87C62BFD86A77A0A26D213E
                            SHA1:7281C2ADB52355DD5C8518575869051D331A466F
                            SHA-256:EFAF06DEC6A5FC55A5831CF57103A8CE8236F1FA7F7885CA93B76D45AE22AD38
                            SHA-512:06D6131A9B823DCEA3396A2AED62248934E74EE4AF9C393D2361271FF12EF5025C92E4A5AF5DBB4EB56A01FD04B0209F34276CEAE8B8FA3ABFC3C3B4D330D710
                            Malicious:false
                            Reputation:unknown
                            URL:"https://fonts.googleapis.com/css?family=Roboto:100,300,400,400i,500,700"
                            Preview:/* cyrillic-ext */.@font-face {. font-family: 'Roboto';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/roboto/v47/KFOKCnqEu92Fr1Mu53ZEC9_Vu3r1gIhOszmOClHrs6ljXfMMLoHQuAX-k2Qn.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C8A, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Roboto';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/roboto/v47/KFOKCnqEu92Fr1Mu53ZEC9_Vu3r1gIhOszmOClHrs6ljXfMMLoHQuAz-k2Qn.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Roboto';. font-style: italic;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/roboto/v47/KFOKCnqEu92Fr1Mu53ZEC9_Vu3r1gIhOszmOClHrs6ljXfMMLoHQuAT-k2Qn.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek */.@font-face {. font-family: '
                            No static file info