Edit tour

Windows Analysis Report
https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflel

Overview

General Information

Sample URL:https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XG
Analysis ID:1676035
Infos:

Detection

Score:0
Range:0 - 100
Confidence:100%

Signatures

URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 2496 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1976 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2424,i,15893107222602938507,1730564585460397409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2408 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.comSample URL: PII: shally@lflelec.com
Source: https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.comHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 52.113.196.254
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com HTTP/1.1Host: lx-virgo-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lx-virgo-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lx-virgo-star-mail.qiye.163.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0 HTTP/1.1Host: lx-sagittarius-star-mail.qiye.163.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Origin: https://lx-virgo-star-mail.qiye.163.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://lx-virgo-star-mail.qiye.163.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0 HTTP/1.1Host: lx-sagittarius-star-mail.qiye.163.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: lx-virgo-star-mail.qiye.163.com
Source: global trafficDNS traffic detected: DNS query: lx-sagittarius-star-mail.qiye.163.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.4:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.210.226.45:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 8.218.184.24:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/2@10/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2424,i,15893107222602938507,1730564585460397409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2408 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2424,i,15893107222602938507,1730564585460397409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2408 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1676035 URL: https://lx-virgo-star-mail.... Startdate: 28/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49708 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 192.178.49.196, 443, 49725, 49748 GOOGLEUS United States 10->15 17 lx-virgo-star-mail.qiye.163.com 8.210.226.45, 443, 49727, 49728 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 10->17 19 lx-sagittarius-star-mail.qiye.163.com 8.218.184.24, 443, 49742, 49743 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://lx-virgo-star-mail.qiye.163.com/favicon.ico0%Avira URL Cloudsafe
https://lx-sagittarius-star-mail.qiye.163.com/api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I00%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
lx-sagittarius-star-mail.qiye.163.com
8.218.184.24
truefalse
    high
    www.google.com
    192.178.49.196
    truefalse
      high
      lx-virgo-star-mail.qiye.163.com
      8.210.226.45
      truefalse
        high
        NameMaliciousAntivirus DetectionReputation
        http://c.pki.goog/r/r4.crlfalse
          high
          https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.comfalse
            unknown
            https://lx-sagittarius-star-mail.qiye.163.com/api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0false
            • Avira URL Cloud: safe
            unknown
            https://lx-virgo-star-mail.qiye.163.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            8.210.226.45
            lx-virgo-star-mail.qiye.163.comSingapore
            45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
            192.178.49.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            8.218.184.24
            lx-sagittarius-star-mail.qiye.163.comSingapore
            45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1676035
            Start date and time:2025-04-28 09:38:05 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 53s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:20
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@21/2@10/4
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.72.142, 172.217.12.131, 192.178.49.174, 74.125.137.84, 192.178.49.206, 142.250.68.78, 142.250.217.142, 142.250.68.234, 192.178.49.202, 142.250.69.10, 192.178.49.170, 72.247.234.254, 84.201.221.36, 142.250.68.227, 184.29.183.29, 20.109.210.53
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, update.googleapis.com, clients.l.google.com, c.pki.goog
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&amp;sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&amp;from=shally@lflelec.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):16
            Entropy (8bit):3.625
            Encrypted:false
            SSDEEP:3:HFn:l
            MD5:418FBC40DEEBD999D02A91F3BC9850B9
            SHA1:A04AB7C83CB2CDF175711BF34C27A0C32F801DC2
            SHA-256:E85E233CE28065F9DE8A6429A42B6BFC4752340EDB2F66AF1B79F1B805549771
            SHA-512:74599CE0567379C67882DCC387D869C2F5340D5F814789A65740C378A85949822118A4C8B842241D297087907CF646271DAB0866E3754291F729C3253185986D
            Malicious:false
            Reputation:low
            URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCSVryEauxHYFEgUNZecJJiE6-ylTGz3tcg==?alt=proto
            Preview:CgkKBw1l5wkmGgA=
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 78
            • 443 (HTTPS)
            • 80 (HTTP)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 28, 2025 09:38:55.875885963 CEST4968180192.168.2.42.17.190.73
            Apr 28, 2025 09:39:03.423542023 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:03.892256021 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:04.578808069 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:05.484993935 CEST4968180192.168.2.42.17.190.73
            Apr 28, 2025 09:39:05.781877041 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:06.971632004 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:06.971679926 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:06.971754074 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:06.971942902 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:06.971956968 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:07.290970087 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:07.291039944 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:07.292493105 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:07.292501926 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:07.292737007 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:07.344002962 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:08.187768936 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:08.638488054 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.638514042 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:08.642370939 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.642410994 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:08.642431974 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.644629955 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.730827093 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.730832100 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:08.730846882 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:08.730850935 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.691903114 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.691973925 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:09.693288088 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:09.693295956 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.693502903 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.693999052 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:09.720309973 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.720388889 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:09.720825911 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:09.720834017 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.721062899 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.736268997 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:09.766304016 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.069112062 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.069135904 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.069181919 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.069212914 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.069289923 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.070045948 CEST49728443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.070074081 CEST443497288.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.182523012 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.224273920 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.557847977 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.557904959 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.559313059 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.559313059 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.748934031 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.748971939 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.752372980 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.752527952 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.752542973 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:10.860271931 CEST49727443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:10.860292912 CEST443497278.210.226.45192.168.2.4
            Apr 28, 2025 09:39:11.723232985 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:11.723295927 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:11.729029894 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:11.729039907 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:11.729238987 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:11.729530096 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:11.776272058 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:12.107554913 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:12.107604980 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:12.107654095 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:12.109386921 CEST49735443192.168.2.48.210.226.45
            Apr 28, 2025 09:39:12.109401941 CEST443497358.210.226.45192.168.2.4
            Apr 28, 2025 09:39:12.188891888 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:12.500719070 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:12.998308897 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:13.113753080 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:14.329262018 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:14.517749071 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.518691063 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.518691063 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.657872915 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.658472061 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.658483028 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.659060955 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.659092903 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.659214973 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.659672976 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.661890030 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.661902905 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.662066936 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.668279886 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.799540997 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.808104992 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.810404062 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.810436010 CEST4434970852.113.196.254192.168.2.4
            Apr 28, 2025 09:39:14.810518026 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:14.810518026 CEST49708443192.168.2.452.113.196.254
            Apr 28, 2025 09:39:15.129091024 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:39:15.276894093 CEST8049739192.178.49.195192.168.2.4
            Apr 28, 2025 09:39:15.277008057 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:39:15.277215004 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:39:15.424752951 CEST8049739192.178.49.195192.168.2.4
            Apr 28, 2025 09:39:15.425167084 CEST8049739192.178.49.195192.168.2.4
            Apr 28, 2025 09:39:15.469551086 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:39:16.735193968 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:17.272708893 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:17.272761106 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:17.272934914 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:17.878216028 CEST49725443192.168.2.4192.178.49.196
            Apr 28, 2025 09:39:17.878235102 CEST44349725192.178.49.196192.168.2.4
            Apr 28, 2025 09:39:19.782655954 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:19.782675982 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:19.782744884 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:19.782948971 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:19.782967091 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:20.777216911 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:20.777373075 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:20.781521082 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:20.781527042 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:20.781754971 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:20.782028913 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:20.824271917 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:21.337270975 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:21.337346077 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:21.338381052 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:21.338606119 CEST49742443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:21.338618994 CEST443497428.218.184.24192.168.2.4
            Apr 28, 2025 09:39:21.547561884 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:39:21.547869921 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:21.547890902 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:21.548118114 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:21.548118114 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:21.548146009 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.527699947 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.527774096 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:22.528290033 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:22.528296947 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.528623104 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.528913975 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:22.576265097 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.609792948 CEST49671443192.168.2.4204.79.197.203
            Apr 28, 2025 09:39:22.904274940 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.904346943 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:22.904397964 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:22.904839039 CEST49743443192.168.2.48.218.184.24
            Apr 28, 2025 09:39:22.904851913 CEST443497438.218.184.24192.168.2.4
            Apr 28, 2025 09:39:31.162475109 CEST49678443192.168.2.420.189.173.27
            Apr 28, 2025 09:40:06.880947113 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:06.880970001 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:06.881048918 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:06.881237984 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:06.881249905 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:07.194293022 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:07.194710016 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:07.194725037 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:15.876271963 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:40:16.023804903 CEST8049739192.178.49.195192.168.2.4
            Apr 28, 2025 09:40:16.023869991 CEST4973980192.168.2.4192.178.49.195
            Apr 28, 2025 09:40:17.192420959 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:17.192476034 CEST44349748192.178.49.196192.168.2.4
            Apr 28, 2025 09:40:17.192523003 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:17.878217936 CEST49748443192.168.2.4192.178.49.196
            Apr 28, 2025 09:40:17.878262043 CEST44349748192.178.49.196192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 28, 2025 09:39:03.101501942 CEST53516441.1.1.1192.168.2.4
            Apr 28, 2025 09:39:03.124713898 CEST53649241.1.1.1192.168.2.4
            Apr 28, 2025 09:39:04.451765060 CEST53572821.1.1.1192.168.2.4
            Apr 28, 2025 09:39:04.602303028 CEST53557571.1.1.1192.168.2.4
            Apr 28, 2025 09:39:06.829547882 CEST5603753192.168.2.41.1.1.1
            Apr 28, 2025 09:39:06.829826117 CEST6071853192.168.2.41.1.1.1
            Apr 28, 2025 09:39:06.969825029 CEST53560371.1.1.1192.168.2.4
            Apr 28, 2025 09:39:06.970416069 CEST53607181.1.1.1192.168.2.4
            Apr 28, 2025 09:39:08.258111000 CEST6146153192.168.2.41.1.1.1
            Apr 28, 2025 09:39:08.258111000 CEST6401153192.168.2.41.1.1.1
            Apr 28, 2025 09:39:08.509020090 CEST53640111.1.1.1192.168.2.4
            Apr 28, 2025 09:39:08.536439896 CEST53614611.1.1.1192.168.2.4
            Apr 28, 2025 09:39:10.306365967 CEST53583761.1.1.1192.168.2.4
            Apr 28, 2025 09:39:10.562572002 CEST6144453192.168.2.41.1.1.1
            Apr 28, 2025 09:39:10.562572002 CEST5857853192.168.2.41.1.1.1
            Apr 28, 2025 09:39:10.703963995 CEST53585781.1.1.1192.168.2.4
            Apr 28, 2025 09:39:10.744520903 CEST53614441.1.1.1192.168.2.4
            Apr 28, 2025 09:39:19.554250002 CEST5828853192.168.2.41.1.1.1
            Apr 28, 2025 09:39:19.554446936 CEST5253353192.168.2.41.1.1.1
            Apr 28, 2025 09:39:19.734183073 CEST53582881.1.1.1192.168.2.4
            Apr 28, 2025 09:39:19.841511965 CEST53525331.1.1.1192.168.2.4
            Apr 28, 2025 09:39:21.358043909 CEST6346853192.168.2.41.1.1.1
            Apr 28, 2025 09:39:21.358253002 CEST5113053192.168.2.41.1.1.1
            Apr 28, 2025 09:39:21.502934933 CEST53634681.1.1.1192.168.2.4
            Apr 28, 2025 09:39:21.549916029 CEST53648921.1.1.1192.168.2.4
            Apr 28, 2025 09:39:21.665014029 CEST53511301.1.1.1192.168.2.4
            Apr 28, 2025 09:39:40.703183889 CEST53625921.1.1.1192.168.2.4
            Apr 28, 2025 09:40:02.438288927 CEST53643991.1.1.1192.168.2.4
            Apr 28, 2025 09:40:03.638765097 CEST53552761.1.1.1192.168.2.4
            Apr 28, 2025 09:40:05.485187054 CEST53513411.1.1.1192.168.2.4
            Apr 28, 2025 09:40:11.602169037 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPChecksumCodeType
            Apr 28, 2025 09:39:04.451838970 CEST192.168.2.41.1.1.1c222(Port unreachable)Destination Unreachable
            Apr 28, 2025 09:39:19.841573954 CEST192.168.2.41.1.1.1c232(Port unreachable)Destination Unreachable
            Apr 28, 2025 09:39:21.665160894 CEST192.168.2.41.1.1.1c232(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 28, 2025 09:39:06.829547882 CEST192.168.2.41.1.1.10x8245Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:06.829826117 CEST192.168.2.41.1.1.10x7cbeStandard query (0)www.google.com65IN (0x0001)false
            Apr 28, 2025 09:39:08.258111000 CEST192.168.2.41.1.1.10xd20aStandard query (0)lx-virgo-star-mail.qiye.163.comA (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:08.258111000 CEST192.168.2.41.1.1.10xbdcbStandard query (0)lx-virgo-star-mail.qiye.163.com65IN (0x0001)false
            Apr 28, 2025 09:39:10.562572002 CEST192.168.2.41.1.1.10x52a3Standard query (0)lx-virgo-star-mail.qiye.163.comA (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:10.562572002 CEST192.168.2.41.1.1.10x8a48Standard query (0)lx-virgo-star-mail.qiye.163.com65IN (0x0001)false
            Apr 28, 2025 09:39:19.554250002 CEST192.168.2.41.1.1.10xc043Standard query (0)lx-sagittarius-star-mail.qiye.163.comA (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:19.554446936 CEST192.168.2.41.1.1.10xbf26Standard query (0)lx-sagittarius-star-mail.qiye.163.com65IN (0x0001)false
            Apr 28, 2025 09:39:21.358043909 CEST192.168.2.41.1.1.10x65f7Standard query (0)lx-sagittarius-star-mail.qiye.163.comA (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:21.358253002 CEST192.168.2.41.1.1.10x940bStandard query (0)lx-sagittarius-star-mail.qiye.163.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 28, 2025 09:39:06.969825029 CEST1.1.1.1192.168.2.40x8245No error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:06.970416069 CEST1.1.1.1192.168.2.40x7cbeNo error (0)www.google.com65IN (0x0001)false
            Apr 28, 2025 09:39:08.536439896 CEST1.1.1.1192.168.2.40xd20aNo error (0)lx-virgo-star-mail.qiye.163.com8.210.226.45A (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:10.744520903 CEST1.1.1.1192.168.2.40x52a3No error (0)lx-virgo-star-mail.qiye.163.com8.210.226.45A (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:19.734183073 CEST1.1.1.1192.168.2.40xc043No error (0)lx-sagittarius-star-mail.qiye.163.com8.218.184.24A (IP address)IN (0x0001)false
            Apr 28, 2025 09:39:21.502934933 CEST1.1.1.1192.168.2.40x65f7No error (0)lx-sagittarius-star-mail.qiye.163.com8.218.184.24A (IP address)IN (0x0001)false
            • lx-virgo-star-mail.qiye.163.com
              • lx-sagittarius-star-mail.qiye.163.com
            • c.pki.goog
            Session IDSource IPSource PortDestination IPDestination Port
            0192.168.2.449739192.178.49.19580
            TimestampBytes transferredDirectionData
            Apr 28, 2025 09:39:15.277215004 CEST200OUTGET /r/r4.crl HTTP/1.1
            Cache-Control: max-age = 3000
            Connection: Keep-Alive
            Accept: */*
            If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
            User-Agent: Microsoft-CryptoAPI/10.0
            Host: c.pki.goog
            Apr 28, 2025 09:39:15.425167084 CEST1242INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
            Cross-Origin-Resource-Policy: cross-origin
            Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
            Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
            Content-Length: 530
            X-Content-Type-Options: nosniff
            Server: sffe
            X-XSS-Protection: 0
            Date: Mon, 28 Apr 2025 07:30:42 GMT
            Expires: Mon, 28 Apr 2025 08:20:42 GMT
            Cache-Control: public, max-age=3000
            Age: 513
            Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
            Content-Type: application/pkix-crl
            Vary: Accept-Encoding
            Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
            Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.4497288.210.226.454431976C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-28 07:39:09 UTC947OUTGET /unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com HTTP/1.1
            Host: lx-virgo-star-mail.qiye.163.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-28 07:39:10 UTC493INHTTP/1.1 200 OK
            Server: nginx/1.20.1
            Date: Mon, 28 Apr 2025 07:39:09 GMT
            Content-Type: text/html
            Content-Length: 8415
            Connection: close
            Vary: Accept-Encoding
            last-modified: Thu, 17 Apr 2025 03:30:39 GMT
            accept-ranges: bytes
            x-content-type-options: nosniff
            x-xss-protection: 1; mode=block
            cache-control: no-cache, no-store, max-age=0, must-revalidate
            pragma: no-cache
            expires: 0
            x-envoy-upstream-service-time: 7
            lingxi-traceid: fbf4d4cb66ba842c9e20b505ba6a470d^750873600000^0
            2025-04-28 07:39:10 UTC8415INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 61 73 65 20 46 6f 72 65 69 67 6e 20 54 72 61 64 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 68 74 6d 6c 2c 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20
            Data Ascii: <!DOCTYPE html><html><head> <meta charset="UTF-8"> <title>Ease Foreign Trade</title> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /> <style> html, body { margin: 0;


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.4497278.210.226.454431976C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-28 07:39:10 UTC891OUTGET /favicon.ico HTTP/1.1
            Host: lx-virgo-star-mail.qiye.163.com
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-28 07:39:10 UTC472INHTTP/1.1 200 OK
            Server: nginx/1.20.1
            Date: Mon, 28 Apr 2025 07:39:10 GMT
            Content-Type: image/x-icon
            Content-Length: 946
            Connection: close
            last-modified: Tue, 22 Apr 2025 08:23:01 GMT
            accept-ranges: bytes
            x-content-type-options: nosniff
            x-xss-protection: 1; mode=block
            cache-control: no-cache, no-store, max-age=0, must-revalidate
            pragma: no-cache
            expires: 0
            x-envoy-upstream-service-time: 5
            lingxi-traceid: aff9e053001dd3432fe25ce380a3a951^750873600000^0
            2025-04-28 07:39:10 UTC946INData Raw: 00 00 01 00 01 00 10 0d 00 00 01 00 20 00 9c 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 1a 00 00 00 01 00 20 00 00 00 00 00 74 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 66 a0 70 1c 46 8f 57 8c 42 ab 87 56 41 ca ba 4f 42 cd bf 62 3b cf c4 7b 36 d0 c6 92 33 d0 c5 a4 2c ce c4 a4 32 d0 c6 a0 3b d2 c8 79 48 d3 ca 2d 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 37 9a 6b 32 2f 81 42 fb 2b 7d 3a ff 2a 85 48 ff 28 94 61 ff 26 a4 7d ff 24 b9 a1 ff 23 c5 b5 ff 22 cd c3 ff 22 cd c2 ff 21 cc c1 ff 26 cd c2 ff 31 cf c5 9e 41 d2 c9 18 00 00 00 00 44 d2 c7 25 2e c1 ad cf 26 a9 85 ff 27 a5 7e fe 28 9e 73 ff 29 96 66 ff 2a 8f 58 ff 2b 85 47 ff 2a 90 5a ff 26 b0 91 ff 23 ca bd ff 22 ce c4 fe 22 cc c1 ff 22 cc c1 ff 30 cf c5 a7 00 00 00 06 34
            Data Ascii: ( tfpFWBVAOBb;{63,2;yH-7k2/B+}:*H(a&}$#""!&1AD%.&'~(s)f*X+G*Z&#"""04


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.4497358.210.226.454431976C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-28 07:39:11 UTC406OUTGET /favicon.ico HTTP/1.1
            Host: lx-virgo-star-mail.qiye.163.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Sec-Fetch-Storage-Access: active
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-28 07:39:12 UTC472INHTTP/1.1 200 OK
            Server: nginx/1.20.1
            Date: Mon, 28 Apr 2025 07:39:11 GMT
            Content-Type: image/x-icon
            Content-Length: 946
            Connection: close
            last-modified: Tue, 22 Apr 2025 08:23:01 GMT
            accept-ranges: bytes
            x-content-type-options: nosniff
            x-xss-protection: 1; mode=block
            cache-control: no-cache, no-store, max-age=0, must-revalidate
            pragma: no-cache
            expires: 0
            x-envoy-upstream-service-time: 5
            lingxi-traceid: 4aa26e49edc3c2a520b3ecdbf931de45^750873600000^0
            2025-04-28 07:39:12 UTC946INData Raw: 00 00 01 00 01 00 10 0d 00 00 01 00 20 00 9c 03 00 00 16 00 00 00 28 00 00 00 10 00 00 00 1a 00 00 00 01 00 20 00 00 00 00 00 74 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 66 a0 70 1c 46 8f 57 8c 42 ab 87 56 41 ca ba 4f 42 cd bf 62 3b cf c4 7b 36 d0 c6 92 33 d0 c5 a4 2c ce c4 a4 32 d0 c6 a0 3b d2 c8 79 48 d3 ca 2d 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 37 9a 6b 32 2f 81 42 fb 2b 7d 3a ff 2a 85 48 ff 28 94 61 ff 26 a4 7d ff 24 b9 a1 ff 23 c5 b5 ff 22 cd c3 ff 22 cd c2 ff 21 cc c1 ff 26 cd c2 ff 31 cf c5 9e 41 d2 c9 18 00 00 00 00 44 d2 c7 25 2e c1 ad cf 26 a9 85 ff 27 a5 7e fe 28 9e 73 ff 29 96 66 ff 2a 8f 58 ff 2b 85 47 ff 2a 90 5a ff 26 b0 91 ff 23 ca bd ff 22 ce c4 fe 22 cc c1 ff 22 cc c1 ff 30 cf c5 a7 00 00 00 06 34
            Data Ascii: ( tfpFWBVAOBb;{63,2;yH-7k2/B+}:*H(a&}$#""!&1AD%.&'~(s)f*X+G*Z&#"""04


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.4497428.218.184.244431976C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-28 07:39:20 UTC806OUTGET /api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0 HTTP/1.1
            Host: lx-sagittarius-star-mail.qiye.163.com
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: */*
            Origin: https://lx-virgo-star-mail.qiye.163.com
            Sec-Fetch-Site: same-site
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Referer: https://lx-virgo-star-mail.qiye.163.com/
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-28 07:39:21 UTC639INHTTP/1.1 200 OK
            Server: nginx/1.20.1
            Date: Mon, 28 Apr 2025 07:39:21 GMT
            Content-Type: application/json;charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept-Encoding
            vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
            access-control-allow-origin: https://lx-virgo-star-mail.qiye.163.com
            access-control-allow-credentials: true
            x-content-type-options: nosniff
            x-xss-protection: 1; mode=block
            cache-control: no-cache, no-store, max-age=0, must-revalidate
            pragma: no-cache
            expires: 0
            x-envoy-upstream-service-time: 174
            lingxi-traceid: ae39574dcec18e8f83ffccd9a277815d^750873600000^0
            2025-04-28 07:39:21 UTC63INData Raw: 33 34 0d 0a 7b 22 64 61 74 61 22 3a 6e 75 6c 6c 2c 22 73 75 63 63 65 73 73 22 3a 74 72 75 65 2c 22 6d 65 73 73 61 67 65 22 3a 6e 75 6c 6c 2c 22 63 6f 64 65 22 3a 30 7d 0d 0a 30 0d 0a 0d 0a
            Data Ascii: 34{"data":null,"success":true,"message":null,"code":0}0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.4497438.218.184.244431976C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-28 07:39:22 UTC604OUTGET /api/pub/edm/unsubscribe?sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0 HTTP/1.1
            Host: lx-sagittarius-star-mail.qiye.163.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Sec-Fetch-Storage-Access: active
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-28 07:39:22 UTC452INHTTP/1.1 200 OK
            Server: nginx/1.20.1
            Date: Mon, 28 Apr 2025 07:39:22 GMT
            Content-Type: application/json;charset=UTF-8
            Transfer-Encoding: chunked
            Connection: close
            Vary: Accept-Encoding
            x-content-type-options: nosniff
            x-xss-protection: 1; mode=block
            cache-control: no-cache, no-store, max-age=0, must-revalidate
            pragma: no-cache
            expires: 0
            x-envoy-upstream-service-time: 2
            lingxi-traceid: 029fc3c2fe99844477377c319764bf96^750873600000^0
            2025-04-28 07:39:22 UTC77INData Raw: 34 32 0d 0a 7b 22 64 61 74 61 22 3a 22 e6 93 8d e4 bd 9c e8 bf 87 e4 ba 8e e9 a2 91 e7 b9 81 22 2c 22 73 75 63 63 65 73 73 22 3a 74 72 75 65 2c 22 6d 65 73 73 61 67 65 22 3a 22 22 2c 22 63 6f 64 65 22 3a 30 7d 0d 0a 30 0d 0a 0d 0a
            Data Ascii: 42{"data":"","success":true,"message":"","code":0}0


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:03:38:57
            Start date:28/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:03:39:01
            Start date:28/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2424,i,15893107222602938507,1730564585460397409,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2408 /prefetch:3
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:03:39:07
            Start date:28/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-virgo-star-mail.qiye.163.com/unsubscribe_en.html?host=lx-sagittarius-star-mail.qiye.163.com&sign=V2.lpefdVB3fBIn5jYbzx4U2YxCwfzF1zhDovOFM95KYRMsmkvPTWGHmJkyVh-kau_GRjEEx_JODZTY9oBQM1wOpa8XGQo36AvuWDSLziO_Vq4ddppSjX7x0lSYg_eA1cu3_2mwzbJaFWeGfFE47CtGSbF3xeZIl5LEobXxIw3R5I0&from=shally@lflelec.com"
            Imagebase:0x7ff786830000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly