Edit tour

Windows Analysis Report
http://Twx.remoteservice.navify.com

Overview

General Information

Sample URL:http://Twx.remoteservice.navify.com
Analysis ID:1674321
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 4040 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4468 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2272,i,13876164410939779329,18436548266366870711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2308 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7012 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Twx.remoteservice.navify.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://twx.remoteservice.navify.com/Thingworx/HomeHTTP Parser: No favicon
Source: https://twx.remoteservice.navify.com/Thingworx/HomeHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.6:49694 version: TLS 1.2
Source: unknownHTTPS traffic detected: 193.58.155.1:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 193.58.155.1:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.91
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /Thingworx HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /Thingworx/ HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET /Thingworx HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET /Thingworx/ HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET /Thingworx/Home HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://twx.remoteservice.navify.com/Thingworx/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://twx.remoteservice.navify.com/Thingworx/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: twx.remoteservice.navify.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: twx.remoteservice.navify.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Fri, 25 Apr 2025 17:06:08 GMTContent-Type: text/htmlContent-Length: 22215Connection: closeCF-Access-Aud: a5494c41ea13fb4b6c718f0a218348967b94e9dff37e0c260f034d5af7d46d9eCF-Access-Domain: twx.remoteservice.navify.comCF-RAY: 935f6de04ea7b829-PHXcf-version: 2017-c8d78b9Referrer-Policy: strict-origin-when-cross-originServer: cloudflare
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.6:49694 version: TLS 1.2
Source: unknownHTTPS traffic detected: 193.58.155.1:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknownHTTPS traffic detected: 193.58.155.1:443 -> 192.168.2.6:49703 version: TLS 1.2
Source: classification engineClassification label: clean0.win@24/8@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2272,i,13876164410939779329,18436548266366870711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2308 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Twx.remoteservice.navify.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2272,i,13876164410939779329,18436548266366870711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2308 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1674321 URL: http://Twx.remoteservice.na... Startdate: 25/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.16 unknown unknown 5->13 15 192.168.2.6, 138, 443, 49694 unknown unknown 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 twx.remoteservice.navify.com 193.58.155.1, 443, 49697, 49698 MAZAYANETPS Switzerland 10->17 19 www.google.com 142.250.69.4, 443, 49694, 49719 GOOGLEUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://Twx.remoteservice.navify.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
twx.remoteservice.navify.com
193.58.155.1
truefalse
    high
    www.google.com
    142.250.69.4
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://twx.remoteservice.navify.com/Thingworx/false
        high
        https://twx.remoteservice.navify.com/Thingworx/Homefalse
          high
          http://c.pki.goog/r/r4.crlfalse
            high
            http://twx.remoteservice.navify.com/false
              high
              https://twx.remoteservice.navify.com/false
                high
                https://twx.remoteservice.navify.com/favicon.icofalse
                  high
                  https://twx.remoteservice.navify.com/Thingworxfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.69.4
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    193.58.155.1
                    twx.remoteservice.navify.comSwitzerland
                    208031MAZAYANETPSfalse
                    IP
                    192.168.2.16
                    192.168.2.6
                    Joe Sandbox version:42.0.0 Malachite
                    Analysis ID:1674321
                    Start date and time:2025-04-25 19:04:57 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 5s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://Twx.remoteservice.navify.com
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:16
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@24/8@6/4
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, TextInputHost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.69.3, 192.178.49.174, 142.251.2.84, 192.178.49.206, 192.178.49.202, 192.178.49.170, 142.250.69.10, 142.250.68.234, 199.232.214.172, 192.178.49.163, 142.250.68.227, 184.29.183.29, 20.12.23.50
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenFile calls found.
                    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                    • VT rate limit hit for: http://Twx.remoteservice.navify.com
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:downloaded
                    Size (bytes):386
                    Entropy (8bit):5.2873892587518645
                    Encrypted:false
                    SSDEEP:12:hnMEwuiuX4wpBk6Qclfhe/FNOHqQRCXxcRyQL:hMNmlBkspe/dQRC0
                    MD5:F427265F7A93565B8AD98838F4EA719A
                    SHA1:94A6B12710EB70E4D14AF457D1204820EF1C8B74
                    SHA-256:6EA478C07F1143D03F05F47C3F63980B2CB0F1C51EE43F08ECD5D4FE6C2887B3
                    SHA-512:295F584E257DC0B4D5D8B0F1328A213D0089A07A2F486B761C7800956DBF2D7F7DB89514FD9B5CE872E0A519C41F822F6A09FEF944E448CBD43E81124B373279
                    Malicious:false
                    Reputation:low
                    URL:https://twx.remoteservice.navify.com/Thingworx/
                    Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">.<html xmlns="http://www.w3.org/1999/xhtml">.<head>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>. <title>Thingworx</title>. <meta HTTP-EQUIV="REFRESH" content="0; url=/Thingworx/Home">.</head>.<body>.Redirecting....</body>.</html>.
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with no line terminators
                    Category:downloaded
                    Size (bytes):16
                    Entropy (8bit):3.875
                    Encrypted:false
                    SSDEEP:3:HDf:jf
                    MD5:1F4E7CC6A67AD8F2A3EA6C11F0CBDAB3
                    SHA1:F9D1CECBEA21D9D48D751A22CAAE8E1698F1E6D2
                    SHA-256:90BBC4E215B563FAF384ADA0239FDAE3A180D1D3720A490770AB7AC676AA86B3
                    SHA-512:7182840C8F22E50BA2C61E4D3EF13A105AABE3610443E8CB40005DA9A691051A2321D56B993D57B6FC1A105E25F0333E364A60479AE0B25338A8AE0867319A86
                    Malicious:false
                    Reputation:low
                    URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCRtDZ49VZjznEgUNXUy4VSEzd7zn0poPMQ==?alt=proto
                    Preview:CgkKBw1dTLhVGgA=
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, Unicode text, UTF-8 text, with very long lines (435), with no line terminators
                    Category:downloaded
                    Size (bytes):439
                    Entropy (8bit):5.3005069836649925
                    Encrypted:false
                    SSDEEP:6:qTthqzcqHCamX6jHzKRwszpuEIRuL5loXFNRXuRYA/bRIM2PLVe/NX96lEUHCaR:qTOUdgH/sI0llokRt/Jq5e/mefu
                    MD5:9A389F3F53BA43A8B3581E929D777635
                    SHA1:197CFE06BD69F659584808FE320E37D066EEEB41
                    SHA-256:E2DF620FF6C76C6529734638E25E9163D8D70F45DF5D3D5807E8D635FA4F3487
                    SHA-512:B535DFB71D51624506EE765F2C652AC9DFB788D702AFA447B4233B4FF8182AECDD8CFCF994F41A1103EB5D115DE705E90C7575DF8F9A7B46F0CEF334439F3ACC
                    Malicious:false
                    Reputation:low
                    URL:https://twx.remoteservice.navify.com/favicon.ico
                    Preview:<!doctype html><html lang="es"><head><title>Estado HTTP 404 . No encontrado</title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>Estado HTTP 404 . No encontrado</h1></body></html>
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, Unicode text, UTF-8 text, with very long lines (5783)
                    Category:downloaded
                    Size (bytes):22215
                    Entropy (8bit):5.065677782130981
                    Encrypted:false
                    SSDEEP:384:nIna2Y4EyaWtY3bI09rcES8QNQcZSjIaHDbHhmhXkk4ByjEl/u0z8c3zxZlYlyxD:CP1tY3U09nZQN103/g6Wj6W0zf3z9zd
                    MD5:B81269AA73A4B1158BACC7BA72598FB3
                    SHA1:872B74AA59BF8FF1C51777AEED3BF614EDEFE455
                    SHA-256:9604F100D025A3A2FBFB3BE72DF7A95208BA0BC899B26D116FB1015D4D20853F
                    SHA-512:5E76F2E165CBD07FD6A3D8B60E6F8C6BF7FF1784E7E09961B3651AFA680493245ADB3FAEE03F370246DA53AF3E932A35CFA870EF085A7759C17FC3C67398BAA0
                    Malicious:false
                    Reputation:low
                    URL:https://twx.remoteservice.navify.com/Thingworx/Home
                    Preview:<!DOCTYPE html>.<html>..<head>. <title>Error . Cloudflare Access</title>. <meta charset="utf-8" />. <meta name="robots" content="noindex" />. <meta name="viewport" content="initial-scale=1, maximum-scale=1, user-scalable=no, width=device-width" />. <style>*{-webkit-box-sizing:inherit;box-sizing:inherit}body,html{min-height:100vh}html{background:;text-align:center;text-rendering:optimizeLegibility;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";line-height:1.5;word-wrap:break-word;-webkit-box-sizing:border-box;box-sizing:border-box;background:#f7f7f8;color:#333}.Content,body{display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-ms-flex-direction:column;flex-direction:column}body{padding:32px;margin:0}.Content{-webkit-box-pack:center;-ms-flex-pack:center;justify-content:center;-webkit-box-align:center;-ms-flex-align:center;align-items:c
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 110
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 25, 2025 19:05:51.112726927 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:05:51.425769091 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:05:52.035157919 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:05:53.238293886 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:05:55.800782919 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:05:59.645370007 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:05:59.957560062 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:00.287837029 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:00.287875891 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:00.287938118 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:00.288271904 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:00.288285017 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:00.566953897 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:00.609313965 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:00.609379053 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:00.610533953 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:00.610543013 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:00.610788107 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:00.613802910 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:06:00.660675049 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:01.714469910 CEST4969780192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.714956045 CEST4969880192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.719676971 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.719712019 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:01.723444939 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.723711014 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.723725080 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:01.772263050 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:01.854347944 CEST8049697193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:01.854460001 CEST4969780192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:01.854742050 CEST8049698193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:01.854804993 CEST4969880192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.018884897 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.018961906 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.024024963 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.024044037 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.024336100 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.026093960 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.068279028 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.937694073 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.937854052 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.937918901 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.938314915 CEST49699443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.938333988 CEST44349699193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.940535069 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.940562963 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:02.940690041 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.940932035 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:02.940943003 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.229913950 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.230134964 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.230165958 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.230267048 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.230273008 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.995999098 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.996068954 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.996124029 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.996830940 CEST49700443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.996848106 CEST44349700193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.998966932 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.999018908 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:03.999115944 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.999253035 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:03.999270916 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.178864956 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:04.290256023 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.290580034 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.290612936 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.290846109 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.290852070 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.553716898 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.553823948 CEST44349701193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.553916931 CEST49701443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.556350946 CEST4969780192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.696355104 CEST8049697193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.713928938 CEST8049697193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.716201067 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.716249943 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.716346979 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.716495991 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:04.716511011 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:04.754690886 CEST4969780192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.006083965 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.006170988 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.010526896 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.010543108 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.010809898 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.011322975 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.052280903 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.524966002 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.525300026 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.527439117 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527445078 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527478933 CEST44349703193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.527492046 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.527580023 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527601957 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527601957 CEST49703443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527754068 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.527761936 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.818289995 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.818717003 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.818742037 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:05.819324017 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:05.819329023 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.612951994 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.613018990 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.613094091 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.613454103 CEST49704443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.613468885 CEST44349704193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.618217945 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.618251085 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.618311882 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.618486881 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.618496895 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.913260937 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.913562059 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.913580894 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:06.913727045 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:06.913732052 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.395391941 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.395528078 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.395577908 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.438581944 CEST49705443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.438621998 CEST44349705193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.499762058 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.499816895 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.499872923 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.500096083 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.500143051 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.500288010 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.500462055 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.500473022 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.500691891 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.500703096 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.790914059 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.791177988 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.791225910 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.791263103 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.791366100 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.791393042 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.791503906 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.791511059 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:07.791565895 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:07.791572094 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.157373905 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.157490015 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.157552958 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.161842108 CEST49706443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.161870003 CEST44349706193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238460064 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238528967 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238575935 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238579988 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.238609076 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238643885 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.238651991 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238693953 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238733053 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.238739967 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.238990068 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239033937 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239032984 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.239047050 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239089012 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.239097118 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239861012 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239897013 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239916086 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.239926100 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.239962101 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.239968061 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.240504980 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.240542889 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.240550041 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.240628958 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.240668058 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.341195107 CEST49707443192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:08.341231108 CEST44349707193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:08.982414007 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:09.940064907 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:06:10.089519978 CEST8049714192.178.49.195192.168.2.6
                    Apr 25, 2025 19:06:10.093410969 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:06:10.093772888 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:06:10.223210096 CEST49672443192.168.2.6204.79.197.203
                    Apr 25, 2025 19:06:10.241758108 CEST8049714192.178.49.195192.168.2.6
                    Apr 25, 2025 19:06:10.242207050 CEST8049714192.178.49.195192.168.2.6
                    Apr 25, 2025 19:06:10.285696030 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:06:10.590512991 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:10.590569973 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:10.590703011 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:11.209881067 CEST49694443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:06:11.209913015 CEST44349694142.250.69.4192.168.2.6
                    Apr 25, 2025 19:06:16.996480942 CEST8049698193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:16.996578932 CEST4969880192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:17.224865913 CEST4969880192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:17.365246058 CEST8049698193.58.155.1192.168.2.6
                    Apr 25, 2025 19:06:18.582748890 CEST49678443192.168.2.620.42.65.91
                    Apr 25, 2025 19:06:49.723839998 CEST4969780192.168.2.6193.58.155.1
                    Apr 25, 2025 19:06:49.863821983 CEST8049697193.58.155.1192.168.2.6
                    Apr 25, 2025 19:07:00.209003925 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:00.209038973 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:00.209093094 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:00.209275007 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:00.209296942 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:00.523330927 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:00.523730993 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:00.523766041 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:10.395797968 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:07:10.513448954 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:10.513505936 CEST44349719142.250.69.4192.168.2.6
                    Apr 25, 2025 19:07:10.513578892 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:10.543981075 CEST8049714192.178.49.195192.168.2.6
                    Apr 25, 2025 19:07:10.544074059 CEST4971480192.168.2.6192.178.49.195
                    Apr 25, 2025 19:07:11.210236073 CEST49719443192.168.2.6142.250.69.4
                    Apr 25, 2025 19:07:11.210268974 CEST44349719142.250.69.4192.168.2.6
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 25, 2025 19:05:56.055205107 CEST53583701.1.1.1192.168.2.6
                    Apr 25, 2025 19:05:56.075093985 CEST53639061.1.1.1192.168.2.6
                    Apr 25, 2025 19:05:57.436077118 CEST53588341.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:00.146440983 CEST5552053192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:00.146692038 CEST5955553192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:00.286724091 CEST53555201.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:00.286786079 CEST53595551.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:01.552041054 CEST6531953192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:01.552336931 CEST5569853192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:01.568778038 CEST6510353192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:01.568989992 CEST5250253192.168.2.61.1.1.1
                    Apr 25, 2025 19:06:01.706752062 CEST53556981.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:01.710124016 CEST53653191.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:01.711189032 CEST53651031.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:01.716177940 CEST53525021.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:08.864984989 CEST53538971.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:14.443190098 CEST53652931.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:33.333275080 CEST53517071.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:55.602910995 CEST53522951.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:55.803257942 CEST53552991.1.1.1192.168.2.6
                    Apr 25, 2025 19:06:57.730135918 CEST138138192.168.2.6192.168.2.255
                    Apr 25, 2025 19:06:58.755840063 CEST53598621.1.1.1192.168.2.6
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 25, 2025 19:06:00.146440983 CEST192.168.2.61.1.1.10x778cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 25, 2025 19:06:00.146692038 CEST192.168.2.61.1.1.10x9d3bStandard query (0)www.google.com65IN (0x0001)false
                    Apr 25, 2025 19:06:01.552041054 CEST192.168.2.61.1.1.10x5397Standard query (0)twx.remoteservice.navify.comA (IP address)IN (0x0001)false
                    Apr 25, 2025 19:06:01.552336931 CEST192.168.2.61.1.1.10xcc18Standard query (0)twx.remoteservice.navify.com65IN (0x0001)false
                    Apr 25, 2025 19:06:01.568778038 CEST192.168.2.61.1.1.10xbd6eStandard query (0)twx.remoteservice.navify.comA (IP address)IN (0x0001)false
                    Apr 25, 2025 19:06:01.568989992 CEST192.168.2.61.1.1.10xf3ebStandard query (0)twx.remoteservice.navify.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 25, 2025 19:06:00.286724091 CEST1.1.1.1192.168.2.60x778cNo error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
                    Apr 25, 2025 19:06:00.286786079 CEST1.1.1.1192.168.2.60x9d3bNo error (0)www.google.com65IN (0x0001)false
                    Apr 25, 2025 19:06:01.710124016 CEST1.1.1.1192.168.2.60x5397No error (0)twx.remoteservice.navify.com193.58.155.1A (IP address)IN (0x0001)false
                    Apr 25, 2025 19:06:01.711189032 CEST1.1.1.1192.168.2.60xbd6eNo error (0)twx.remoteservice.navify.com193.58.155.1A (IP address)IN (0x0001)false
                    • twx.remoteservice.navify.com
                    • c.pki.goog
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.649697193.58.155.1804468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Apr 25, 2025 19:06:04.556350946 CEST443OUTGET / HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Apr 25, 2025 19:06:04.713928938 CEST499INHTTP/1.1 301 Moved Permanently
                    Date: Fri, 25 Apr 2025 17:06:04 GMT
                    Content-Type: text/html
                    Content-Length: 167
                    Connection: keep-alive
                    Cache-Control: max-age=3600
                    Expires: Fri, 25 Apr 2025 18:06:04 GMT
                    Location: https://twx.remoteservice.navify.com/
                    Vary: Accept-Encoding
                    Server: cloudflare
                    CF-RAY: 935f6dcaec541a78-PHX
                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                    Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>cloudflare</center></body></html>
                    Apr 25, 2025 19:06:49.723839998 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination Port
                    1192.168.2.649714192.178.49.19580
                    TimestampBytes transferredDirectionData
                    Apr 25, 2025 19:06:10.093772888 CEST200OUTGET /r/r4.crl HTTP/1.1
                    Cache-Control: max-age = 3000
                    Connection: Keep-Alive
                    Accept: */*
                    If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                    User-Agent: Microsoft-CryptoAPI/10.0
                    Host: c.pki.goog
                    Apr 25, 2025 19:06:10.242207050 CEST1242INHTTP/1.1 200 OK
                    Accept-Ranges: bytes
                    Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                    Cross-Origin-Resource-Policy: cross-origin
                    Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                    Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                    Content-Length: 530
                    X-Content-Type-Options: nosniff
                    Server: sffe
                    X-XSS-Protection: 0
                    Date: Fri, 25 Apr 2025 17:00:42 GMT
                    Expires: Fri, 25 Apr 2025 17:50:42 GMT
                    Cache-Control: public, max-age=3000
                    Age: 328
                    Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                    Content-Type: application/pkix-crl
                    Vary: Accept-Encoding
                    Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                    Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.649699193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:02 UTC678OUTGET / HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-04-25 17:06:02 UTC277INHTTP/1.1 302 Moved Temporarily
                    Date: Fri, 25 Apr 2025 17:06:02 GMT
                    Content-Type: text/html
                    Transfer-Encoding: chunked
                    Connection: close
                    Location: https://twx.remoteservice.navify.com/Thingworx
                    CF-Ray: 935f6dbc2da7598b-PHX
                    CF-Cache-Status: DYNAMIC
                    Server: cloudflare
                    2025-04-25 17:06:02 UTC144INData Raw: 38 61 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a
                    Data Ascii: 8a<html><head><title>302 Found</title></head><body><center><h1>302 Found</h1></center><hr><center>nginx</center></body></html>
                    2025-04-25 17:06:02 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.649700193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:03 UTC687OUTGET /Thingworx HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    2025-04-25 17:06:03 UTC382INHTTP/1.1 302
                    Date: Fri, 25 Apr 2025 17:06:03 GMT
                    Transfer-Encoding: chunked
                    Connection: close
                    Set-Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d; Path=/; Secure; HttpOnly; SameSite=None
                    Location: /Thingworx/
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    cf-cache-status: DYNAMIC
                    Server: cloudflare
                    CF-RAY: 935f6dc3cc4097fd-PHX
                    2025-04-25 17:06:03 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.649701193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:04 UTC761OUTGET /Thingworx/ HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.649703193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:05 UTC751OUTGET / HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
                    2025-04-25 17:06:05 UTC277INHTTP/1.1 302 Moved Temporarily
                    Date: Fri, 25 Apr 2025 17:06:05 GMT
                    Content-Type: text/html
                    Transfer-Encoding: chunked
                    Connection: close
                    Location: https://twx.remoteservice.navify.com/Thingworx
                    CF-Ray: 935f6dcedaf35711-PHX
                    CF-Cache-Status: DYNAMIC
                    Server: cloudflare
                    2025-04-25 17:06:05 UTC144INData Raw: 38 61 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 0d 0a
                    Data Ascii: 8a<html><head><title>302 Found</title></head><body><center><h1>302 Found</h1></center><hr><center>nginx</center></body></html>
                    2025-04-25 17:06:05 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.649704193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:05 UTC760OUTGET /Thingworx HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
                    2025-04-25 17:06:06 UTC264INHTTP/1.1 302
                    Date: Fri, 25 Apr 2025 17:06:06 GMT
                    Transfer-Encoding: chunked
                    Connection: close
                    Location: /Thingworx/
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    cf-cache-status: DYNAMIC
                    Server: cloudflare
                    CF-RAY: 935f6dd3ff9ed2c0-PHX
                    2025-04-25 17:06:06 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.649705193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:06 UTC761OUTGET /Thingworx/ HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
                    2025-04-25 17:06:07 UTC478INHTTP/1.1 200
                    Date: Fri, 25 Apr 2025 17:06:07 GMT
                    Content-Type: text/html
                    Transfer-Encoding: chunked
                    Connection: close
                    X-Content-Type-Options: nosniff
                    X-XSS-Protection: 1; mode=block
                    Content-Security-Policy: frame-ancestors 'self'
                    X-Frame-Options: SAMEORIGIN
                    Accept-Ranges: bytes
                    Last-Modified: Sat, 05 Apr 2025 09:59:08 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    cf-cache-status: DYNAMIC
                    Server: cloudflare
                    CF-RAY: 935f6ddac8df0111-PHX
                    2025-04-25 17:06:07 UTC393INData Raw: 31 38 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 74 72 61 6e 73 69 74 69 6f 6e 61 6c 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 2f 3e 0a 20 20 20 20
                    Data Ascii: 182<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
                    2025-04-25 17:06:07 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    6192.168.2.649707193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:07 UTC810OUTGET /Thingworx/Home HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-Dest: document
                    Referer: https://twx.remoteservice.navify.com/Thingworx/
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
                    2025-04-25 17:06:08 UTC385INHTTP/1.1 403 Forbidden
                    Date: Fri, 25 Apr 2025 17:06:08 GMT
                    Content-Type: text/html
                    Content-Length: 22215
                    Connection: close
                    CF-Access-Aud: a5494c41ea13fb4b6c718f0a218348967b94e9dff37e0c260f034d5af7d46d9e
                    CF-Access-Domain: twx.remoteservice.navify.com
                    CF-RAY: 935f6de04ea7b829-PHX
                    cf-version: 2017-c8d78b9
                    Referrer-Policy: strict-origin-when-cross-origin
                    Server: cloudflare
                    2025-04-25 17:06:08 UTC984INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 e3 83 bb 20 43 6c 6f 75 64 66 6c 61 72 65 20 41 63 63 65 73 73 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 22 20 2f 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 20 2f 3e 0a 20
                    Data Ascii: <!DOCTYPE html><html><head> <title>Error Cloudflare Access</title> <meta charset="utf-8" /> <meta name="robots" content="noindex" /> <meta name="viewport" content="initial-scale=1, maximum-scale=1, user-scalable=no, width=device-width" />
                    2025-04-25 17:06:08 UTC1369INData Raw: 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 6d 61 72 67 69 6e 3a 33 32 70 78 3b 2d 77 65 62 6b 69 74 2d 62 6f 78 2d 66 6c 65 78 3a 31 3b 2d 6d 73 2d 66 6c 65 78 2d 70 6f 73 69 74 69 76 65 3a 31 3b 66 6c 65 78 2d 67 72 6f 77 3a 31 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 37 36 38 70 78 29 7b 2e 43 6f 6e 74 65 6e 74 7b 70 61 64 64 69 6e 67 3a 30 3b 6d 61 72 67 69 6e 3a 33 32 70 78 20 30 7d 7d 2e 41 75 74 68 42 6f 78 7b 6d 61 78 2d 77 69 64 74 68 3a 31 30 30 25 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 35 70 78 3b 62 6f 72 64 65 72 3a 31 70 78 20 73 6f 6c 69 64 20 23 65 61 65 62 65 62 3b 2d 77 65 62 6b 69 74 2d 62 6f 78 2d 73 68 61 64 6f
                    Data Ascii: er;align-items:center;margin:32px;-webkit-box-flex:1;-ms-flex-positive:1;flex-grow:1}@media screen and (max-width:768px){.Content{padding:0;margin:32px 0}}.AuthBox{max-width:100%;background:#fff;border-radius:5px;border:1px solid #eaebeb;-webkit-box-shado
                    2025-04-25 17:06:08 UTC1369INData Raw: 37 65 37 65 37 65 3b 2d 77 65 62 6b 69 74 2d 62 6f 78 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 2d 6d 73 2d 66 6c 65 78 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 67 61 70 3a 31 72 65 6d 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 69 6e 2d 77 69 64 74 68 3a 39 30 63 68 29 7b 2e 44 65 62 75 67 44 65 74 61 69 6c 73 7b 6d 69 6e 2d 77 69 64 74 68 3a 37 35 63 68 7d 2e 72 65 73 70 6f 6e 73 69 76 65 2d 69 6e 66 6f 7b 77 69 64 74 68 3a 31 30 30 25 7d 7d 2e 43 6f 70 79 44 61 74 61 42 74 6e 2c 2e 53 68 6f 77 44 65 74 61 69 6c 73 42 74 6e 7b 70 61 64 64 69 6e 67 3a 31 30
                    Data Ascii: 7e7e7e;-webkit-box-align:center;-ms-flex-align:center;align-items:center;justify-content:center;position:relative;gap:1rem}@media screen and (min-width:90ch){.DebugDetails{min-width:75ch}.responsive-info{width:100%}}.CopyDataBtn,.ShowDetailsBtn{padding:10
                    2025-04-25 17:06:08 UTC1369INData Raw: 6f 61 72 73 65 29 7b 2e 41 63 63 65 73 73 4c 6f 67 6f 7b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 32 65 6d 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 65 6d 7d 2e 4d 65 73 73 61 67 65 7b 6d 61 78 2d 77 69 64 74 68 3a 39 30 25 7d 7d 3c 2f 73 74 79 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 3e 22 75 73 65 20 73 74 72 69 63 74 22 3b 66 75 6e 63 74 69 6f 6e 20 73 68 6f 77 44 65 74 61 69 6c 73 28 29 7b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 64 65 62 75 67 44 65 74 61 69 6c 73 22 29 2e 73 74 79 6c 65 2e 64 69 73 70 6c 61 79 3d 22 66 6c 65 78 22 3b 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 73 68 6f 77 44 65 74 61 69 6c 73 42 74 6e 22 29 3b 73 68 6f 77 44 65 74 61 69 6c 73 42 74 6e 2e 73 74 79 6c 65 2e
                    Data Ascii: oarse){.AccessLogo{margin-bottom:2em;margin-top:1em}.Message{max-width:90%}}</style> <script>"use strict";function showDetails(){document.getElementById("debugDetails").style.display="flex";document.getElementById("showDetailsBtn");showDetailsBtn.style.
                    2025-04-25 17:06:08 UTC1369INData Raw: 34 2d 35 2e 32 39 33 20 33 2e 30 30 33 20 30 20 34 2e 34 37 34 20 31 2e 36 39 38 20 34 2e 37 30 32 20 33 2e 39 35 39 68 2d 32 2e 30 36 33 63 2d 2e 31 38 32 2d 31 2e 31 35 33 2d 2e 39 32 35 2d 32 2e 31 34 2d 32 2e 35 39 33 2d 32 2e 31 34 2d 31 2e 35 39 33 20 30 2d 32 2e 38 32 31 20 31 2e 33 33 35 2d 32 2e 38 30 36 20 33 2e 34 39 20 30 20 32 2e 31 38 33 20 31 2e 32 31 33 20 33 2e 34 37 33 20 32 2e 38 32 20 33 2e 34 37 33 7a 6d 35 2e 36 31 32 20 31 2e 37 32 39 56 36 2e 33 34 33 68 32 2e 30 37 38 76 31 30 2e 37 36 39 48 38 39 2e 37 32 7a 6d 36 2e 39 31 37 2d 37 2e 35 30 37 63 32 2e 33 30 35 20 30 20 33 2e 38 32 32 20 31 2e 35 33 31 20 33 2e 38 32 32 20 33 2e 37 36 20 30 20 32 2e 32 33 2d 31 2e 35 31 37 20 33 2e 38 32 33 2d 33 2e 38 32 32 20 33 2e 38 32 33 2d
                    Data Ascii: 4-5.293 3.003 0 4.474 1.698 4.702 3.959h-2.063c-.182-1.153-.925-2.14-2.593-2.14-1.593 0-2.821 1.335-2.806 3.49 0 2.183 1.213 3.473 2.82 3.473zm5.612 1.729V6.343h2.078v10.769H89.72zm6.917-7.507c2.305 0 3.822 1.531 3.822 3.76 0 2.23-1.517 3.823-3.822 3.823-
                    2025-04-25 17:06:08 UTC1369INData Raw: 33 35 2d 2e 34 37 31 2d 31 2e 33 36 35 2d 31 2e 33 39 36 2d 31 2e 33 36 35 2d 2e 37 38 38 20 30 2d 31 2e 33 30 34 2e 33 37 39 2d 31 2e 33 38 20 31 2e 30 33 68 2d 31 2e 38 38 31 63 2e 31 33 37 2d 31 2e 36 35 32 20 31 2e 34 32 36 2d 32 2e 36 30 38 20 33 2e 33 32 31 2d 32 2e 36 30 38 68 2e 30 30 31 7a 6d 2d 2e 34 31 20 36 2e 30 38 31 63 31 2e 30 39 32 20 30 20 31 2e 37 34 35 2d 2e 36 38 33 20 31 2e 37 34 35 2d 31 2e 32 37 34 76 2d 2e 34 37 68 2d 31 2e 30 37 38 63 2d 31 2e 31 35 32 20 30 2d 31 2e 37 35 39 2e 33 30 33 2d 31 2e 37 35 39 2e 39 37 20 30 20 2e 34 37 2e 33 36 34 2e 37 37 34 20 31 2e 30 39 32 2e 37 37 34 7a 6d 39 2e 30 35 35 2d 36 2e 30 38 32 63 2e 31 36 37 20 30 20 2e 33 37 39 2e 30 31 35 2e 34 37 2e 30 36 31 6c 2d 2e 30 31 35 20 32 2e 30 33 33 63
                    Data Ascii: 35-.471-1.365-1.396-1.365-.788 0-1.304.379-1.38 1.03h-1.881c.137-1.652 1.426-2.608 3.321-2.608h.001zm-.41 6.081c1.092 0 1.745-.683 1.745-1.274v-.47h-1.078c-1.152 0-1.759.303-1.759.97 0 .47.364.774 1.092.774zm9.055-6.082c.167 0 .379.015.47.061l-.015 2.033c
                    2025-04-25 17:06:08 UTC1369INData Raw: 68 2d 2e 30 30 31 7a 6d 32 31 2e 32 38 39 2d 37 2e 30 38 76 2e 37 34 38 68 2d 39 2e 39 32 38 63 2e 32 38 38 20 32 2e 31 35 39 20 31 2e 35 35 34 20 33 2e 32 35 32 20 33 2e 33 39 36 20 33 2e 32 35 32 20 31 2e 38 39 39 20 30 20 32 2e 35 39 2d 2e 39 37 38 20 32 2e 38 32 2d 31 2e 37 32 36 68 33 2e 36 35 36 63 2d 2e 34 36 32 20 32 2e 34 34 36 2d 32 2e 34 31 38 20 34 2e 38 30 36 2d 36 2e 36 37 38 20 34 2e 38 30 36 2d 34 2e 32 38 38 20 30 2d 36 2e 39 39 32 2d 32 2e 39 36 34 2d 36 2e 39 39 32 2d 37 2e 31 36 36 20 30 2d 34 2e 32 36 20 32 2e 39 36 33 2d 37 2e 32 32 33 20 37 2e 30 35 2d 37 2e 32 32 33 20 34 2e 32 38 38 20 30 20 36 2e 36 37 36 20 32 2e 39 39 32 20 36 2e 36 37 36 20 37 2e 33 31 7a 6d 2d 36 2e 36 34 37 2d 34 2e 33 37 34 63 2d 31 2e 35 38 33 20 30 2d 32
                    Data Ascii: h-.001zm21.289-7.08v.748h-9.928c.288 2.159 1.554 3.252 3.396 3.252 1.899 0 2.59-.978 2.82-1.726h3.656c-.462 2.446-2.418 4.806-6.678 4.806-4.288 0-6.992-2.964-6.992-7.166 0-4.26 2.963-7.223 7.05-7.223 4.288 0 6.676 2.992 6.676 7.31zm-6.647-4.374c-1.583 0-2
                    2025-04-25 17:06:08 UTC1369INData Raw: 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 20 73 72 63 3d 22 2e 2e 2f 69 6d 61 67 65 73 2f 62 61 72 72 79 5f 77 68 69 74 65 70 61 70 65 72 2e 73 76 67 22 3e 3c 70 61 74 68 20 6f 70 61 63 69 74 79 3d 22 2e 31 22 20 64 3d 22 4d 31 35 37 2e 30 36 33 20 31 31 32 2e 39 30 31 63 2d 2e 31 34 36 2e 31 30 36 2d 2e 32 38 2e 32 30 39 2d 2e 34 32 32 2e 33 30 39 2d 2e 35 32 37 2e 33 37 31 2d 31 2e 30 37 38 2e 37 30 37 2d 31 2e 36 35 20 31 2e 30 30 34 2d 32 2e 39 39 37 20 31 2e 35 37 35 2d 36 2e 36 39 31 20 32 2e 33 34 35 2d 31 30 2e 32 38 39 20 32 2e 38 36 38 2d 38 2e 30 37 20 31 2e 31 37 34 2d 31 36 2e 33 30 38 20 31 2e 34 30 32 2d 32 34 2e 35 31 32 20 31 2e 36 32 35 2d 32 32 2e 31 36 36 2e 36 30 37 2d 34 34 2e 33 38 37 20 31 2e 32 31 33 2d 36 36
                    Data Ascii: /www.w3.org/2000/svg" src="../images/barry_whitepaper.svg"><path opacity=".1" d="M157.063 112.901c-.146.106-.28.209-.422.309-.527.371-1.078.707-1.65 1.004-2.997 1.575-6.691 2.345-10.289 2.868-8.07 1.174-16.308 1.402-24.512 1.625-22.166.607-44.387 1.213-66
                    2025-04-25 17:06:08 UTC1369INData Raw: 37 56 32 36 2e 39 34 38 7a 22 20 66 69 6c 6c 3d 22 23 66 66 66 22 2f 3e 3c 6d 61 73 6b 20 69 64 3d 22 61 63 63 65 73 73 2d 72 65 73 6f 6c 76 65 72 2d 6e 6f 2d 6c 6f 63 61 74 69 6f 6e 2d 73 76 67 22 20 6d 61 73 6b 2d 74 79 70 65 3d 22 61 6c 70 68 61 22 20 6d 61 73 6b 55 6e 69 74 73 3d 22 75 73 65 72 53 70 61 63 65 4f 6e 55 73 65 22 20 78 3d 22 35 33 22 20 79 3d 22 32 30 22 20 77 69 64 74 68 3d 22 37 32 22 20 68 65 69 67 68 74 3d 22 36 33 22 3e 3c 70 61 74 68 20 64 3d 22 4d 31 32 33 2e 30 35 34 20 33 33 2e 38 30 31 76 34 36 2e 35 33 6c 2d 33 2e 39 36 31 2d 32 2e 31 38 33 2d 2e 37 32 34 2d 2e 33 39 38 2d 2e 37 32 34 2e 33 39 38 2d 35 2e 34 35 33 20 33 2e 30 30 35 2d 35 2e 33 31 33 2d 32 2e 39 39 37 2d 2e 37 37 35 2d 2e 34 33 38 2d 2e 37 35 35 2e 34 37 31 2d
                    Data Ascii: 7V26.948z" fill="#fff"/><mask id="access-resolver-no-location-svg" mask-type="alpha" maskUnits="userSpaceOnUse" x="53" y="20" width="72" height="63"><path d="M123.054 33.801v46.53l-3.961-2.183-.724-.398-.724.398-5.453 3.005-5.313-2.997-.775-.438-.755.471-
                    2025-04-25 17:06:08 UTC1369INData Raw: 31 2e 33 32 33 76 2d 32 2e 36 31 34 7a 22 20 66 69 6c 6c 3d 22 23 34 45 35 32 35 35 22 2f 3e 3c 70 61 74 68 20 64 3d 22 4d 33 33 2e 32 36 39 20 31 37 2e 35 34 37 63 2e 32 33 38 2d 2e 36 34 2e 39 35 2d 2e 39 36 37 20 31 2e 35 39 31 2d 2e 37 32 39 6c 31 33 2e 32 37 20 34 2e 39 33 36 61 31 2e 32 33 38 20 31 2e 32 33 38 20 30 20 30 20 31 2d 2e 38 36 32 20 32 2e 33 32 6c 2d 31 33 2e 32 37 2d 34 2e 39 33 35 61 31 2e 32 33 38 20 31 2e 32 33 38 20 30 20 30 20 31 2d 2e 37 33 2d 31 2e 35 39 32 7a 4d 34 31 2e 30 35 37 20 37 2e 36 37 37 61 31 2e 32 33 38 20 31 2e 32 33 38 20 30 20 30 20 31 20 31 2e 37 35 2d 2e 30 31 36 6c 31 30 2e 31 30 33 20 39 2e 39 32 61 31 2e 32 33 38 20 31 2e 32 33 38 20 30 20 30 20 31 2d 31 2e 37 33 35 20 31 2e 37 36 37 6c 2d 31 30 2e 31 30 32
                    Data Ascii: 1.323v-2.614z" fill="#4E5255"/><path d="M33.269 17.547c.238-.64.95-.967 1.591-.729l13.27 4.936a1.238 1.238 0 0 1-.862 2.32l-13.27-4.935a1.238 1.238 0 0 1-.73-1.592zM41.057 7.677a1.238 1.238 0 0 1 1.75-.016l10.103 9.92a1.238 1.238 0 0 1-1.735 1.767l-10.102


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    7192.168.2.649706193.58.155.14434468C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2025-04-25 17:06:07 UTC702OUTGET /favicon.ico HTTP/1.1
                    Host: twx.remoteservice.navify.com
                    Connection: keep-alive
                    sec-ch-ua-platform: "Windows"
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
                    sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
                    sec-ch-ua-mobile: ?0
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://twx.remoteservice.navify.com/Thingworx/
                    Accept-Encoding: gzip, deflate, br, zstd
                    Accept-Language: en-US,en;q=0.9
                    Cookie: SERVER=1745600764.854.51.51313|0a02a0dfa3bdc416c4ab1acf2f9f7e0d
                    2025-04-25 17:06:08 UTC376INHTTP/1.1 404
                    Date: Fri, 25 Apr 2025 17:06:08 GMT
                    Content-Type: text/html;charset=utf-8
                    Transfer-Encoding: chunked
                    Connection: close
                    Content-Language: es
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    CF-Cache-Status: HIT
                    Expires: Fri, 25 Apr 2025 21:06:08 GMT
                    Cache-Control: public, max-age=14400
                    Server: cloudflare
                    CF-RAY: 935f6de04ba542d9-PHX
                    2025-04-25 17:06:08 UTC446INData Raw: 31 62 37 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 73 22 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 45 73 74 61 64 6f 20 48 54 54 50 20 34 30 34 20 e2 80 93 20 4e 6f 20 65 6e 63 6f 6e 74 72 61 64 6f 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 54 61 68 6f 6d 61 2c 41 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 3b 7d 20 68 31 2c 20 68 32 2c 20 68 33 2c 20 62 20 7b 63 6f 6c 6f 72 3a 77 68 69 74 65 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 32 35 44 37 36 3b 7d 20 68 31 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 32 70 78 3b 7d 20 68 32 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 36 70 78 3b 7d 20 68 33
                    Data Ascii: 1b7<!doctype html><html lang="es"><head><title>Estado HTTP 404 No encontrado</title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3
                    2025-04-25 17:06:08 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0050100MB

                    Click to jump to process

                    Target ID:1
                    Start time:13:05:51
                    Start date:25/04/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff63b000000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:13:05:54
                    Start date:25/04/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2272,i,13876164410939779329,18436548266366870711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2308 /prefetch:3
                    Imagebase:0x7ff63b000000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:12
                    Start time:13:06:00
                    Start date:25/04/2025
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Twx.remoteservice.navify.com"
                    Imagebase:0x7ff63b000000
                    File size:3'388'000 bytes
                    MD5 hash:E81F54E6C1129887AEA47E7D092680BF
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly