Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report


General Information

Sample name:PaymentOnline.html
Analysis ID:1500509


Range:0 - 100


HTML document with suspicious name
HTML file submission containing password form
Phishing site detected (based on image similarity)
Phishing site detected (based on logo match)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML title does not match URL
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
None HTTPS page querying sensitive user data (password, username or email)


  • System is w10x64
  • chrome.exe (PID: 4520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\PaymentOnline.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2008,i,10137650121201936708,14751184556041639990,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results


Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlMatcher: Found strong image similarity, brand: MICROSOFT
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlMatcher: Template: microsoft matched
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: Number of links: 0
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: <input type="password" .../> found but no <form action="...
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: Title: se does not match URL
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: Has password / email / username input fields
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: <input type="password" .../> found
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: Joe Sandbox ViewIP Address:
Source: Joe Sandbox ViewIP Address:
Source: Joe Sandbox ViewIP Address:
Source: Joe Sandbox ViewIP Address:
Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: global trafficHTTP traffic detected: GET /npm/@emailjs/browser@3/dist/email.min.js HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ip.js?var=userip HTTP/1.1Host: l2.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ip.js?var=userip HTTP/1.1Host: l2.ioConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=CyU75V7dEdNgGPP&MD=GouCRbga HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=CyU75V7dEdNgGPP&MD=GouCRbga HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: l2.io
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: PaymentOnline.htmlString found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
Source: chromecache_64.2.drString found in binary or memory: https://api.emailjs.com
Source: PaymentOnline.htmlString found in binary or memory: https://cdn.jsdelivr.net/npm/
Source: chromecache_67.2.dr, chromecache_64.2.drString found in binary or memory: https://dashboard.emailjs.com/admin
Source: chromecache_67.2.dr, chromecache_64.2.drString found in binary or memory: https://dashboard.emailjs.com/admin/account
Source: chromecache_67.2.dr, chromecache_64.2.drString found in binary or memory: https://dashboard.emailjs.com/admin/templates
Source: PaymentOnline.htmlString found in binary or memory: https://getbootstrap.com)
Source: PaymentOnline.htmlString found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
Source: PaymentOnline.htmlString found in binary or memory: https://l2.io/ip.js?var=userip
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2

System Summary

Source: Name includes: PaymentOnline.htmlInitial sample: payment
Source: classification engineClassification label: mal56.phis.winHTML@24/9@10/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\PaymentOnline.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2008,i,10137650121201936708,14751184556041639990,262144 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2008,i,10137650121201936708,14751184556041639990,262144 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior

Stealing of Sensitive Information

Source: file:///C:/Users/user/Desktop/PaymentOnline.htmlHTTP Parser: file:///C:/Users/user/Desktop/PaymentOnline.html
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend


  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
https://github.com/twbs/bootstrap/blob/master/LICENSE)0%Avira URL Cloudsafe
https://cdn.jsdelivr.net/npm/0%Avira URL Cloudsafe
https://getbootstrap.com)0%Avira URL Cloudsafe
https://cdn.jsdelivr.net/npm/@emailjs/browser@3/dist/email.min.js0%Avira URL Cloudsafe
file:///C:/Users/user/Desktop/PaymentOnline.html0%Avira URL Cloudsafe
https://l2.io/ip.js?var=userip0%Avira URL Cloudsafe
https://api.emailjs.com0%Avira URL Cloudsafe
https://dashboard.emailjs.com/admin/templates0%Avira URL Cloudsafe
https://dashboard.emailjs.com/admin/account0%Avira URL Cloudsafe
https://dashboard.emailjs.com/admin0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
          NameMaliciousAntivirus DetectionReputation
          • Avira URL Cloud: safe
          • Avira URL Cloud: safe
          • Avira URL Cloud: safe
          NameSourceMaliciousAntivirus DetectionReputation
          • Avira URL Cloud: safe
          • Avira URL Cloud: safe
          https://dashboard.emailjs.com/admin/accountchromecache_67.2.dr, chromecache_64.2.drfalse
          • Avira URL Cloud: safe
          • Avira URL Cloud: safe
          https://dashboard.emailjs.com/admin/templateschromecache_67.2.dr, chromecache_64.2.drfalse
          • Avira URL Cloud: safe
          • Avira URL Cloud: safe
          https://dashboard.emailjs.com/adminchromecache_67.2.dr, chromecache_64.2.drfalse
          • Avira URL Cloud: safe
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious

          jsdelivr.map.fastly.netUnited States



          www.google.comUnited States

          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1500509
          Start date and time:2024-08-28 15:33:49 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 5m 26s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowshtmlcookbook.jbs
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Sample name:PaymentOnline.html
          Cookbook Comments:
          • Found application associated with file extension: .html
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted):,,,,,,,,,,,,,,,,,,,,,,,,,
          • Excluded domains from analysis (whitelisted): clients1.google.com, cdn.jsdelivr.net.cdn.cloudflare.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ajax.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, optimizationguide-pa.googleapis.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: PaymentOnline.html
          No simulations
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
 Expiration Notification.msgGet hashmaliciousUnknownBrowse
            https://google.mg/url?hl=en&q=https://google.nr/url?q=Gl7qws6TcZ&rct=4214&sa=t&esrc=vax&source=Gl7qws6TcZ&cd=Nzpn8b&cad=Gl7qws6TcZD5&ved=Gl7qws6TcZ84214G&uact=82299&url=amp%2Fgoogle.com.pg/amp/cli.re/rp5Y1r#YW5kcmV3QGhlZWRkaWdpdGFsbWVkaWEuY29t%2F&opi=256371986142&usg=lxfGUQNysmkDx&source=gmail&ust=5108318229914681&usg=AOGl7qws6TcZjng81rOWFwZGl7qws6TcZqR81Get hashmaliciousHTMLPhisherBrowse
              mmclaughlin-In Service Agreement-41918.pdfGet hashmaliciousHTMLPhisherBrowse
                mbda-us.comAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                  https://berajpaints.com.pk/tag/dolor/Get hashmaliciousUnknownBrowse
                    http://jop2024.sciencesconf.org/Get hashmaliciousUnknownBrowse
                      file.exeGet hashmaliciousUnknownBrowse
                        mbda-us.comAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                          Proforma.Invoice.Payment.$$.htmlGet hashmaliciousUnknownBrowse
                            https://hattenforlag.seGet hashmaliciousUnknownBrowse
                              • www.l2.io/ip
                              6dqTzK7uUB.exeGet hashmaliciousUnknownBrowse
                              • www.l2.io/ip
                              PR9Hc4n9Vg.exeGet hashmaliciousUnknownBrowse
                              • www.l2.io/ip
                              Xkly3iW7wH.exeGet hashmaliciousUnknownBrowse
                              • www.l2.io/ip
                              6G3bMss9Bl.exeGet hashmaliciousUnknownBrowse
                              • www.l2.io/ip
                              20202237F.htmlGet hashmaliciousHTMLPhisherBrowse
                              • l2.io/ip.js?var=userip
                                http://claimlive0.pages.dev/Get hashmaliciousUnknownBrowse
                                  DOC-80697077.pdfGet hashmaliciousHTMLPhisherBrowse
                                    https://files.fm/u/vtrxvgdh6wGet hashmaliciousGuLoaderBrowse
                                      http://ebay.to/3u2gAmeGet hashmaliciousUnknownBrowse
                                        http://o62arw.dsjpropertymanagementllc.comGet hashmaliciousEvilProxy, HTMLPhisherBrowse
                                          https://request-label-1356355851.pages.dev/robots.txt/Get hashmaliciousUnknownBrowse
                                            https://help-extensin-coinbse.webflow.io/Get hashmaliciousUnknownBrowse
                                              https://buy-korea-online.vercel.app/?web=th.park@hdel.co.krGet hashmaliciousUnknownBrowse
                                                http://6wuo11ea9pufk7b81cbzel3jw5iijs6wuo11ea9pufk7b81cbzel3jw5iijs.s3-website-us-east-1.amazonaws.comGet hashmaliciousUnknownBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  jsdelivr.map.fastly.netCXWk52EmUt.exeGet hashmaliciousUnknownBrowse
                                                  http://pub-10050726d25949d8bd6cb438a8b6b09c.r2.dev/home.htmlGet hashmaliciousUnknownBrowse
                                                  http://get-verified-free-badge.vercel.app/Get hashmaliciousUnknownBrowse
                                                  https://hamimtalukdar.github.io/Facebook-Login-To-LinkGet hashmaliciousHTMLPhisherBrowse
                                                  https://mellifluous-squirrel-aca5c4.netlify.app/Get hashmaliciousUnknownBrowse
                                                  https://www.unitek-products.com/products/1-5m-hdmi-v2-1-cableGet hashmaliciousUnknownBrowse
                                                  http://claimlive0.pages.dev/Get hashmaliciousUnknownBrowse
                                                  https://pub-d7ea140b75d84515876a7b3907716f0b.r2.dev/OTDISDHFHDJ728783YEBDJHDHDI7092065674-AAHkRTWk91gKycvF_QD3tylL-zHMyVJ083E%207092065674-AAHkRTWk91gKycvF_QD3tylL-zHMyVJ083E%207092065674-AAHkRTWk91gKycvF_QD3tylL-zHMyVJ083DHD834GHF8.html?$deeplink_path=/paystubs/78b0e9e4-d2bc-4f7e-b4da-9d23f146a29a&_branch_match_id=1343911699625856863&_branch_referrer=H4sIAAAAAAAAA21NwU6EMBD9mvVWcEtZwGRjICAsh03MxJTtZdPSQhVUQkGyf29RT4Y5zMx7894bPU2DeXDdt9lMy%20fYGYcPg9O/fnTu4w4TqdSwguvAJ33c4aeB38w0C2PXIBT3KlIESSxqRJpAIUEkR5HEXrMnB44jfmczGt73gtfddR77o17/7bzY%20te0WSBi5aEkai%209hviEhL44hKT2PE9gP2iUM2JHqi%20rfqaQFmlBL9kpOwEqIanOVcLO7B%205qfntdPOWQQoAVZUCYwBpamEcWya2haCA3L7N/%20aGPWGshNLey9bwlusizuMLLWjZ8lYbvdwWndMfM8ALzYoSHD29999vIfWFewEAAA==Get hashmaliciousOutlook Phishing, HTMLPhisherBrowse
                                                  DOC-71275297.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  DOC-80697077.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  l2.iohttps://rogue-orange-foe.glitch.me/public/USANFCU.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  https://orchid-pineapple-lead.glitch.me/public/navyfederal.htmlGet hashmaliciousUnknownBrowse
                                                  Investec Payment-Copy.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  https://sassy-magnificent-antimatter.glitch.me/public/nfcu703553.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  https://futuristic-gem-wood.glitch.me/public/sm5cde.HTMGet hashmaliciousHTMLPhisherBrowse
                                                  https://tarry-foggy-contraption.glitch.me/public/sm5cde.HTMGet hashmaliciousHTMLPhisherBrowse
                                                  https://phase-enthusiastic-wallaby.glitch.me/public/RRENFCONL0.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  https://petalite-crocus-mitten.glitch.me/public/nfcu703553.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  file.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  https://www.uploadhub.io/ZFoF4yMt1IvJbMd/fileGet hashmaliciousHTMLPhisherBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  FASTLYUSmmclaughlin-In Service Agreement-41918.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  mbda-us.comAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  https://berajpaints.com.pk/tag/dolor/Get hashmaliciousUnknownBrowse
                                                  mbda-us.comAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  Proforma.Invoice.Payment.$$.htmlGet hashmaliciousUnknownBrowse
                                                  https://pharmakon-my.sharepoint.com/:f:/g/personal/338im_apoteket_dk/Eq4jY345UJRKi6ZZAILr_qwBOqxx0J6kY0J-kac06geioQ?e=XPAoa6%20pharmakon-my.sharepoint.comGet hashmaliciousHTMLPhisherBrowse
                                                  External VM-Transcript Caller Left 3 CALLMSGS 000047Secs 2808.eml.msgGet hashmaliciousHTMLPhisherBrowse
                                                  https://zngw.officeinvoicedoc.com/DhpuIGet hashmaliciousHTMLPhisherBrowse
                                                  https://silverangelshomes.com/res444.php?4-68747470733a2f2f684a456d2e6c64656e626572616e2e636f6d2f4d33306830536a4f2f-Get hashmaliciousHTMLPhisherBrowse
                                                  https://nr-srpack-dk-payment-conformations.fushenq.com/Get hashmaliciousHTMLPhisherBrowse
                                                  DECKNET-ASFRhttps://rogue-orange-foe.glitch.me/public/USANFCU.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  https://orchid-pineapple-lead.glitch.me/public/navyfederal.htmlGet hashmaliciousUnknownBrowse
                                                  Investec Payment-Copy.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  https://sassy-magnificent-antimatter.glitch.me/public/nfcu703553.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  https://futuristic-gem-wood.glitch.me/public/sm5cde.HTMGet hashmaliciousHTMLPhisherBrowse
                                                  https://tarry-foggy-contraption.glitch.me/public/sm5cde.HTMGet hashmaliciousHTMLPhisherBrowse
                                                  https://phase-enthusiastic-wallaby.glitch.me/public/RRENFCONL0.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  https://petalite-crocus-mitten.glitch.me/public/nfcu703553.HTMLGet hashmaliciousHTMLPhisherBrowse
                                                  file.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  https://www.uploadhub.io/ZFoF4yMt1IvJbMd/fileGet hashmaliciousHTMLPhisherBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  28a2c9bd18a11de089ef85a160da29e4Password Expiration Notification.msgGet hashmaliciousUnknownBrowse
                                                  https://google.mg/url?hl=en&q=https://google.nr/url?q=Gl7qws6TcZ&rct=4214&sa=t&esrc=vax&source=Gl7qws6TcZ&cd=Nzpn8b&cad=Gl7qws6TcZD5&ved=Gl7qws6TcZ84214G&uact=82299&url=amp%2Fgoogle.com.pg/amp/cli.re/rp5Y1r#YW5kcmV3QGhlZWRkaWdpdGFsbWVkaWEuY29t%2F&opi=256371986142&usg=lxfGUQNysmkDx&source=gmail&ust=5108318229914681&usg=AOGl7qws6TcZjng81rOWFwZGl7qws6TcZqR81Get hashmaliciousHTMLPhisherBrowse
                                                  mmclaughlin-In Service Agreement-41918.pdfGet hashmaliciousHTMLPhisherBrowse
                                                  https://berajpaints.com.pk/tag/dolor/Get hashmaliciousUnknownBrowse
                                                  http://jop2024.sciencesconf.org/Get hashmaliciousUnknownBrowse
                                                  file.exeGet hashmaliciousUnknownBrowse
                                                  mbda-us.comAudiowav012.htmlGet hashmaliciousHTMLPhisherBrowse
                                                  Proforma.Invoice.Payment.$$.htmlGet hashmaliciousUnknownBrowse
                                                  https://hattenforlag.seGet hashmaliciousUnknownBrowse
                                                  https://pharmakon-my.sharepoint.com/:f:/g/personal/338im_apoteket_dk/Eq4jY345UJRKi6ZZAILr_qwBOqxx0J6kY0J-kac06geioQ?e=XPAoa6%20pharmakon-my.sharepoint.comGet hashmaliciousHTMLPhisherBrowse
                                                  No context
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with very long lines (2058), with no line terminators
                                                  Size (bytes):2058
                                                  Entropy (8bit):5.2275519102374925
                                                  Reputation:moderate, very likely benign file
                                                  Preview:(()=>{"use strict";var e={d:(t,r)=>{for(var i in r)e.o(r,i)&&!e.o(t,i)&&Object.defineProperty(t,i,{enumerable:!0,get:r[i]})},o:(e,t)=>Object.prototype.hasOwnProperty.call(e,t),r:e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})}},t={};e.r(t),e.d(t,{default:()=>l,init:()=>i,send:()=>a,sendForm:()=>d});const r={_origin:"https://api.emailjs.com"},i=function(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"https://api.emailjs.com";r._userID=e,r._origin=t},s=(e,t,r)=>{if(!e)throw"The public key is required. Visit https://dashboard.emailjs.com/admin/account";if(!t)throw"The service ID is required. Visit https://dashboard.emailjs.com/admin";if(!r)throw"The template ID is required. Visit https://dashboard.emailjs.com/admin/templates";return!0};class o{constructor(e){this.status=e?e.status:0,this.text=e?e.responseText:"Network Error"}}const n=function(e,t){let i=argume
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with very long lines (32065)
                                                  Size (bytes):85578
                                                  Entropy (8bit):5.366055229017455
                                                  Reputation:high, very likely benign file
                                                  Preview:/*! jQuery v2.2.4 | (c) jQuery Foundation | jquery.org/license */.!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="2.2.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.call
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with no line terminators
                                                  Size (bytes):23
                                                  Entropy (8bit):3.9361804341297555
                                                  Reputation:moderate, very likely benign file
                                                  Preview:userip = "";
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with very long lines (2058), with no line terminators
                                                  Size (bytes):2058
                                                  Entropy (8bit):5.2275519102374925
                                                  Reputation:moderate, very likely benign file
                                                  Preview:(()=>{"use strict";var e={d:(t,r)=>{for(var i in r)e.o(r,i)&&!e.o(t,i)&&Object.defineProperty(t,i,{enumerable:!0,get:r[i]})},o:(e,t)=>Object.prototype.hasOwnProperty.call(e,t),r:e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})}},t={};e.r(t),e.d(t,{default:()=>l,init:()=>i,send:()=>a,sendForm:()=>d});const r={_origin:"https://api.emailjs.com"},i=function(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"https://api.emailjs.com";r._userID=e,r._origin=t},s=(e,t,r)=>{if(!e)throw"The public key is required. Visit https://dashboard.emailjs.com/admin/account";if(!t)throw"The service ID is required. Visit https://dashboard.emailjs.com/admin";if(!r)throw"The template ID is required. Visit https://dashboard.emailjs.com/admin/templates";return!0};class o{constructor(e){this.status=e?e.status:0,this.text=e?e.responseText:"Network Error"}}const n=function(e,t){let i=argume
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with no line terminators
                                                  Size (bytes):23
                                                  Entropy (8bit):3.9361804341297555
                                                  Reputation:moderate, very likely benign file
                                                  Preview:userip = "";
                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  File Type:ASCII text, with very long lines (32065)
                                                  Size (bytes):85578
                                                  Entropy (8bit):5.366055229017455
                                                  Preview:/*! jQuery v2.2.4 | (c) jQuery Foundation | jquery.org/license */.!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="2.2.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.call
                                                  File type:HTML document, ASCII text, with very long lines (755)
                                                  Entropy (8bit):6.111868428475651
                                                  • Scalable Vector Graphics (18501/1) 24.18%
                                                  • HyperText Markup Language (12001/1) 15.69%
                                                  • HyperText Markup Language (12001/1) 15.69%
                                                  • HyperText Markup Language (11501/1) 15.03%
                                                  • HyperText Markup Language (11501/1) 15.03%
                                                  File name:PaymentOnline.html
                                                  File size:658'162 bytes
                                                  File Content Preview:<html lang="en">.<head>. <meta http-equiv="x-ua-compatible" content="EmulateIE9" />.<meta charset="utf-8" />.<meta.name="viewport".content="width=device-width, initial-scale=1, shrink-to-fit=no"./>..<title>se</title>.<meta http-equiv="imagetoolbar" conte
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Aug 28, 2024 15:34:53.933428049 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:53.933465004 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:53.933521032 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:53.933806896 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:53.933823109 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:53.943955898 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:53.943984985 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:53.944039106 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:53.944179058 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:53.944195032 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.398724079 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.399036884 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.399068117 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.400221109 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.400296926 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.402446985 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.402502060 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.403145075 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.403152943 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.443428040 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.582561970 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.582632065 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.582674980 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.582685947 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.582720995 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.585067987 CEST49733443192.168.2.4151.101.65.229
                                                  Aug 28, 2024 15:34:54.585093021 CEST44349733151.101.65.229192.168.2.4
                                                  Aug 28, 2024 15:34:54.653398991 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.653661013 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.653702974 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.654553890 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.654608011 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.656378031 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.656435966 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.656713963 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.656724930 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.719806910 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.909252882 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.909307957 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.909380913 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.911895037 CEST49735443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.911917925 CEST44349735195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.978106976 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.978147030 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:54.978256941 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.978521109 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:54.978538036 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.680939913 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.699471951 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:56.699512005 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.700611115 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.700681925 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:56.718624115 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:56.718687057 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.737344980 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:56.737371922 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.785554886 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:56.944195032 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.944262981 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:56.944317102 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:58.116324902 CEST49739443192.168.2.4195.80.159.133
                                                  Aug 28, 2024 15:34:58.116358995 CEST44349739195.80.159.133192.168.2.4
                                                  Aug 28, 2024 15:34:58.331118107 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:58.331166029 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:58.331218958 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:58.332170010 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:58.332189083 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:58.469166040 CEST49672443192.168.2.4173.222.162.32
                                                  Aug 28, 2024 15:34:58.469209909 CEST44349672173.222.162.32192.168.2.4
                                                  Aug 28, 2024 15:34:58.647200108 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:58.647254944 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:34:58.647344112 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:58.649341106 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:58.649353981 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:34:58.967837095 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:58.968907118 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:58.968931913 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:58.969872952 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:58.969927073 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:59.025577068 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:59.025660992 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:59.173609972 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:59.173630953 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:34:59.228882074 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.228938103 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:34:59.229026079 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.230926037 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:34:59.230990887 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:59.233485937 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.233515024 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:34:59.240334034 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:59.240350008 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:34:59.240566015 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:34:59.361144066 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:34:59.361285925 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:34:59.899564028 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:34:59.899640083 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.902463913 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.902486086 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:34:59.902744055 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:34:59.943010092 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:34:59.988502026 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:00.064095020 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.108500957 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.175785065 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:00.175836086 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:00.175946951 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:00.176054955 CEST49748443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:00.176074982 CEST44349748184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:00.255182028 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255206108 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255213976 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255250931 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255275965 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255280018 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.255294085 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255326033 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255348921 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.255348921 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.255372047 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.255532026 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255539894 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255589008 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.255598068 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.255966902 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:00.256017923 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:00.385075092 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:00.385143042 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:00.386276960 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:00.386703014 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:00.386727095 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.024204016 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:01.024246931 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:01.024261951 CEST49747443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:01.024269104 CEST4434974720.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:01.065443039 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.065505028 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.069560051 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.069571972 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.069802999 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.075484037 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.120498896 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.343781948 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.343842030 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.343910933 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.344667912 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.344690084 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:01.344701052 CEST49752443192.168.2.4184.28.90.27
                                                  Aug 28, 2024 15:35:01.344707012 CEST44349752184.28.90.27192.168.2.4
                                                  Aug 28, 2024 15:35:02.845473051 CEST4972380192.168.2.488.221.110.91
                                                  Aug 28, 2024 15:35:02.850847006 CEST804972388.221.110.91192.168.2.4
                                                  Aug 28, 2024 15:35:02.850919008 CEST4972380192.168.2.488.221.110.91
                                                  Aug 28, 2024 15:35:08.875667095 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:08.875724077 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:08.875824928 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:08.877718925 CEST49746443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:08.877744913 CEST44349746172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:37.610922098 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:37.610982895 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:37.611304998 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:37.611515045 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:37.611526012 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.194200993 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.194276094 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.198779106 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.198788881 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.198987961 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.209124088 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.252505064 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.402059078 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.402085066 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.402098894 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.402143955 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.402158976 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.402198076 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.402216911 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.403614998 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.403662920 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.403681993 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.403687000 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.403696060 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.403712034 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.403736115 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.407826900 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.407840967 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:38.407860041 CEST49761443192.168.2.420.12.23.50
                                                  Aug 28, 2024 15:35:38.407865047 CEST4434976120.12.23.50192.168.2.4
                                                  Aug 28, 2024 15:35:51.748606920 CEST4972480192.168.2.493.184.221.240
                                                  Aug 28, 2024 15:35:51.753916025 CEST804972493.184.221.240192.168.2.4
                                                  Aug 28, 2024 15:35:51.754108906 CEST4972480192.168.2.493.184.221.240
                                                  Aug 28, 2024 15:35:58.558233023 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:58.558278084 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:58.558600903 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:58.558600903 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:58.558629990 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:59.188517094 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:59.189122915 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:59.189136028 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:59.189446926 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:59.190026045 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:35:59.190082073 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:35:59.232681036 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:36:09.109613895 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:36:09.109673977 CEST44349763172.217.16.132192.168.2.4
                                                  Aug 28, 2024 15:36:09.109982014 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:36:10.203836918 CEST49763443192.168.2.4172.217.16.132
                                                  Aug 28, 2024 15:36:10.203866005 CEST44349763172.217.16.132192.168.2.4
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Aug 28, 2024 15:34:53.847583055 CEST53610981.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.923221111 CEST5981453192.
                                                  Aug 28, 2024 15:34:53.923341990 CEST5194753192.
                                                  Aug 28, 2024 15:34:53.923662901 CEST6503053192.
                                                  Aug 28, 2024 15:34:53.923768997 CEST4972853192.
                                                  Aug 28, 2024 15:34:53.928849936 CEST53509521.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.932811975 CEST53598141.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.932821989 CEST53519471.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.932832003 CEST53614691.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.932841063 CEST53650301.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:53.943648100 CEST53497281.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:54.591972113 CEST5693553192.
                                                  Aug 28, 2024 15:34:54.592441082 CEST6346153192.
                                                  Aug 28, 2024 15:34:54.599035978 CEST53634611.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:54.932773113 CEST53601541.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:54.958683014 CEST5355953192.
                                                  Aug 28, 2024 15:34:54.958820105 CEST5221053192.
                                                  Aug 28, 2024 15:34:54.965404987 CEST53535591.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:54.976342916 CEST53522101.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:55.360589981 CEST53614401.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:58.320451021 CEST6438653192.
                                                  Aug 28, 2024 15:34:58.320703030 CEST5367353192.
                                                  Aug 28, 2024 15:34:58.328872919 CEST53536731.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:34:58.328980923 CEST53643861.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:35:03.317987919 CEST138138192.168.2.4192.168.2.255
                                                  Aug 28, 2024 15:35:06.491921902 CEST53515801.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:35:12.009068012 CEST53565961.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:35:30.932885885 CEST53650061.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:35:53.697453022 CEST53550031.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:35:53.866185904 CEST53581641.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:36:22.771543980 CEST53542011.1.1.1192.168.2.4
                                                  Aug 28, 2024 15:37:08.913265944 CEST53528011.1.1.1192.168.2.4
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Aug 28, 2024 15:34:53.923221111 CEST192. query (0)cdn.jsdelivr.netA (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.923341990 CEST192. query (0)cdn.jsdelivr.net65IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.923662901 CEST192. query (0)l2.ioA (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.923768997 CEST192. query (0)l2.io65IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.591972113 CEST192. query (0)cdn.jsdelivr.netA (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.592441082 CEST192. query (0)cdn.jsdelivr.net65IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.958683014 CEST192. query (0)l2.ioA (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.958820105 CEST192. query (0)l2.io65IN (0x0001)false
                                                  Aug 28, 2024 15:34:58.320451021 CEST192. query (0)www.google.comA (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:58.320703030 CEST192. query (0)www.google.com65IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Aug 28, 2024 15:34:53.932811975 CEST1.1.1.1192.168.2.40x734dNo error (0)cdn.jsdelivr.netjsdelivr.map.fastly.netCNAME (Canonical name)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932811975 CEST1.1.1.1192.168.2.40x734dNo error (0)jsdelivr.map.fastly.net151.101.65.229A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932811975 CEST1.1.1.1192.168.2.40x734dNo error (0)jsdelivr.map.fastly.net151.101.129.229A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932811975 CEST1.1.1.1192.168.2.40x734dNo error (0)jsdelivr.map.fastly.net151.101.193.229A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932811975 CEST1.1.1.1192.168.2.40x734dNo error (0)jsdelivr.map.fastly.net151.101.1.229A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932821989 CEST1.1.1.1192.168.2.40x5f1No error (0)cdn.jsdelivr.netjsdelivr.map.fastly.netCNAME (Canonical name)IN (0x0001)false
                                                  Aug 28, 2024 15:34:53.932841063 CEST1.1.1.1192.168.2.40x5ae0No error (0)l2.io195.80.159.133A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.598712921 CEST1.1.1.1192.168.2.40xef98No error (0)cdn.jsdelivr.netcdn.jsdelivr.net.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.599035978 CEST1.1.1.1192.168.2.40x1d2fNo error (0)cdn.jsdelivr.netjsdelivr.map.fastly.netCNAME (Canonical name)IN (0x0001)false
                                                  Aug 28, 2024 15:34:54.965404987 CEST1.1.1.1192.168.2.40x5399No error (0)l2.io195.80.159.133A (IP address)IN (0x0001)false
                                                  Aug 28, 2024 15:34:58.328872919 CEST1.1.1.1192.168.2.40xd776No error (0)www.google.com65IN (0x0001)false
                                                  Aug 28, 2024 15:34:58.328980923 CEST1.1.1.1192.168.2.40x944bNo error (0)www.google.com172.217.16.132A (IP address)IN (0x0001)false
                                                  • cdn.jsdelivr.net
                                                  • l2.io
                                                  • slscr.update.microsoft.com
                                                  • fs.microsoft.com
                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.449733151.101.65.2294434928C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:34:54 UTC520OUTGET /npm/@emailjs/browser@3/dist/email.min.js HTTP/1.1
                                                  Host: cdn.jsdelivr.net
                                                  Connection: keep-alive
                                                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                  sec-ch-ua-mobile: ?0
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36
                                                  sec-ch-ua-platform: "Windows"
                                                  Accept: */*
                                                  Sec-Fetch-Site: cross-site
                                                  Sec-Fetch-Mode: no-cors
                                                  Sec-Fetch-Dest: script
                                                  Accept-Encoding: gzip, deflate, br
                                                  Accept-Language: en-US,en;q=0.9
                                                  2024-08-28 13:34:54 UTC757INHTTP/1.1 200 OK
                                                  Connection: close
                                                  Content-Length: 2058
                                                  Access-Control-Allow-Origin: *
                                                  Access-Control-Expose-Headers: *
                                                  Timing-Allow-Origin: *
                                                  Cache-Control: public, max-age=604800, s-maxage=43200
                                                  Cross-Origin-Resource-Policy: cross-origin
                                                  X-Content-Type-Options: nosniff
                                                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                  Content-Type: application/javascript; charset=utf-8
                                                  X-JSD-Version: 3.12.1
                                                  X-JSD-Version-Type: version
                                                  ETag: W/"80a-PXSZ1xOJiieY9EnYs1KNQJRHUgg"
                                                  Accept-Ranges: bytes
                                                  Age: 25433
                                                  Date: Wed, 28 Aug 2024 13:34:54 GMT
                                                  X-Served-By: cache-fra-etou8220134-FRA, cache-ewr-kewr1740025-EWR
                                                  X-Cache: HIT, MISS
                                                  Vary: Accept-Encoding
                                                  alt-svc: h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
                                                  2024-08-28 13:34:54 UTC1378INData Raw: 28 28 29 3d 3e 7b 22 75 73 65 20 73 74 72 69 63 74 22 3b 76 61 72 20 65 3d 7b 64 3a 28 74 2c 72 29 3d 3e 7b 66 6f 72 28 76 61 72 20 69 20 69 6e 20 72 29 65 2e 6f 28 72 2c 69 29 26 26 21 65 2e 6f 28 74 2c 69 29 26 26 4f 62 6a 65 63 74 2e 64 65 66 69 6e 65 50 72 6f 70 65 72 74 79 28 74 2c 69 2c 7b 65 6e 75 6d 65 72 61 62 6c 65 3a 21 30 2c 67 65 74 3a 72 5b 69 5d 7d 29 7d 2c 6f 3a 28 65 2c 74 29 3d 3e 4f 62 6a 65 63 74 2e 70 72 6f 74 6f 74 79 70 65 2e 68 61 73 4f 77 6e 50 72 6f 70 65 72 74 79 2e 63 61 6c 6c 28 65 2c 74 29 2c 72 3a 65 3d 3e 7b 22 75 6e 64 65 66 69 6e 65 64 22 21 3d 74 79 70 65 6f 66 20 53 79 6d 62 6f 6c 26 26 53 79 6d 62 6f 6c 2e 74 6f 53 74 72 69 6e 67 54 61 67 26 26 4f 62 6a 65 63 74 2e 64 65 66 69 6e 65 50 72 6f 70 65 72 74 79 28 65 2c 53
                                                  Data Ascii: (()=>{"use strict";var e={d:(t,r)=>{for(var i in r)e.o(r,i)&&!e.o(t,i)&&Object.defineProperty(t,i,{enumerable:!0,get:r[i]})},o:(e,t)=>Object.prototype.hasOwnProperty.call(e,t),r:e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,S
                                                  2024-08-28 13:34:54 UTC680INData Raw: 2c 61 3d 28 65 2c 74 2c 69 2c 6f 29 3d 3e 7b 63 6f 6e 73 74 20 61 3d 6f 7c 7c 72 2e 5f 75 73 65 72 49 44 3b 73 28 61 2c 65 2c 74 29 3b 63 6f 6e 73 74 20 64 3d 7b 6c 69 62 5f 76 65 72 73 69 6f 6e 3a 22 33 2e 31 32 2e 31 22 2c 75 73 65 72 5f 69 64 3a 61 2c 73 65 72 76 69 63 65 5f 69 64 3a 65 2c 74 65 6d 70 6c 61 74 65 5f 69 64 3a 74 2c 74 65 6d 70 6c 61 74 65 5f 70 61 72 61 6d 73 3a 69 7d 3b 72 65 74 75 72 6e 20 6e 28 22 2f 61 70 69 2f 76 31 2e 30 2f 65 6d 61 69 6c 2f 73 65 6e 64 22 2c 4a 53 4f 4e 2e 73 74 72 69 6e 67 69 66 79 28 64 29 2c 7b 22 43 6f 6e 74 65 6e 74 2d 74 79 70 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 73 6f 6e 22 7d 29 7d 2c 64 3d 28 65 2c 74 2c 69 2c 6f 29 3d 3e 7b 63 6f 6e 73 74 20 61 3d 6f 7c 7c 72 2e 5f 75 73 65 72 49 44 2c 64
                                                  Data Ascii: ,a=(e,t,i,o)=>{const a=o||r._userID;s(a,e,t);const d={lib_version:"3.12.1",user_id:a,service_id:e,template_id:t,template_params:i};return n("/api/v1.0/email/send",JSON.stringify(d),{"Content-type":"application/json"})},d=(e,t,i,o)=>{const a=o||r._userID,d

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  1192.168.2.449735195.80.159.1334434928C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:34:54 UTC485OUTGET /ip.js?var=userip HTTP/1.1
                                                  Host: l2.io
                                                  Connection: keep-alive
                                                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                  sec-ch-ua-mobile: ?0
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36
                                                  sec-ch-ua-platform: "Windows"
                                                  Accept: */*
                                                  Sec-Fetch-Site: cross-site
                                                  Sec-Fetch-Mode: no-cors
                                                  Sec-Fetch-Dest: script
                                                  Accept-Encoding: gzip, deflate, br
                                                  Accept-Language: en-US,en;q=0.9
                                                  2024-08-28 13:34:54 UTC167INHTTP/1.1 200 OK
                                                  Date: Wed, 28 Aug 2024 13:34:54 GMT
                                                  Server: Apache/2.4.38 (Debian)
                                                  Content-Length: 23
                                                  Connection: close
                                                  Content-Type: text/html; charset=UTF-8
                                                  2024-08-28 13:34:54 UTC23INData Raw: 75 73 65 72 69 70 20 3d 20 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 3b
                                                  Data Ascii: userip = "";

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  2192.168.2.449739195.80.159.1334434928C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:34:56 UTC345OUTGET /ip.js?var=userip HTTP/1.1
                                                  Host: l2.io
                                                  Connection: keep-alive
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36
                                                  Accept: */*
                                                  Sec-Fetch-Site: none
                                                  Sec-Fetch-Mode: cors
                                                  Sec-Fetch-Dest: empty
                                                  Accept-Encoding: gzip, deflate, br
                                                  Accept-Language: en-US,en;q=0.9
                                                  2024-08-28 13:34:56 UTC167INHTTP/1.1 200 OK
                                                  Date: Wed, 28 Aug 2024 13:34:56 GMT
                                                  Server: Apache/2.4.38 (Debian)
                                                  Content-Length: 23
                                                  Connection: close
                                                  Content-Type: text/html; charset=UTF-8
                                                  2024-08-28 13:34:56 UTC23INData Raw: 75 73 65 72 69 70 20 3d 20 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 3b
                                                  Data Ascii: userip = "";

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:34:59 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept: */*
                                                  Accept-Encoding: identity
                                                  User-Agent: Microsoft BITS/7.8
                                                  Host: fs.microsoft.com
                                                  2024-08-28 13:35:00 UTC467INHTTP/1.1 200 OK
                                                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                  Content-Type: application/octet-stream
                                                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                  Server: ECAcc (lpl/EF06)
                                                  X-CID: 11
                                                  X-Ms-ApiVersion: Distribute 1.2
                                                  X-Ms-Region: prod-weu-z1
                                                  Cache-Control: public, max-age=244857
                                                  Date: Wed, 28 Aug 2024 13:35:00 GMT
                                                  Connection: close
                                                  X-CID: 2

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:35:00 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=CyU75V7dEdNgGPP&MD=GouCRbga HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept: */*
                                                  User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                  Host: slscr.update.microsoft.com
                                                  2024-08-28 13:35:00 UTC560INHTTP/1.1 200 OK
                                                  Cache-Control: no-cache
                                                  Pragma: no-cache
                                                  Content-Type: application/octet-stream
                                                  Expires: -1
                                                  Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                  ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                  MS-CorrelationId: 40e8f7b7-c931-4826-8385-37850ec0af2f
                                                  MS-RequestId: 0a3ccce1-b60e-497f-9123-8b8fedbe964d
                                                  MS-CV: w3BkM+nKbUma+Ry3.0
                                                  X-Microsoft-SLSClientCache: 2880
                                                  Content-Disposition: attachment; filename=environment.cab
                                                  X-Content-Type-Options: nosniff
                                                  Date: Wed, 28 Aug 2024 13:34:59 GMT
                                                  Connection: close
                                                  Content-Length: 24490
                                                  2024-08-28 13:35:00 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                  Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                  2024-08-28 13:35:00 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                  Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:35:01 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept: */*
                                                  Accept-Encoding: identity
                                                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                                  Range: bytes=0-2147483646
                                                  User-Agent: Microsoft BITS/7.8
                                                  Host: fs.microsoft.com
                                                  2024-08-28 13:35:01 UTC515INHTTP/1.1 200 OK
                                                  ApiVersion: Distribute 1.1
                                                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                  Content-Type: application/octet-stream
                                                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                  Server: ECAcc (lpl/EF06)
                                                  X-CID: 11
                                                  X-Ms-ApiVersion: Distribute 1.2
                                                  X-Ms-Region: prod-weu-z1
                                                  Cache-Control: public, max-age=244865
                                                  Date: Wed, 28 Aug 2024 13:35:01 GMT
                                                  Content-Length: 55
                                                  Connection: close
                                                  X-CID: 2
                                                  2024-08-28 13:35:01 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}

                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  TimestampBytes transferredDirectionData
                                                  2024-08-28 13:35:38 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=CyU75V7dEdNgGPP&MD=GouCRbga HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Accept: */*
                                                  User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                  Host: slscr.update.microsoft.com
                                                  2024-08-28 13:35:38 UTC560INHTTP/1.1 200 OK
                                                  Cache-Control: no-cache
                                                  Pragma: no-cache
                                                  Content-Type: application/octet-stream
                                                  Expires: -1
                                                  Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                  ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                                                  MS-CorrelationId: 33676f2f-28b7-420a-824e-5d21fe579577
                                                  MS-RequestId: 9d613e95-60c9-4db3-ada4-dcce81ee5d50
                                                  MS-CV: BLSafpflV0+D1UeK.0
                                                  X-Microsoft-SLSClientCache: 1440
                                                  Content-Disposition: attachment; filename=environment.cab
                                                  X-Content-Type-Options: nosniff
                                                  Date: Wed, 28 Aug 2024 13:35:37 GMT
                                                  Connection: close
                                                  Content-Length: 30005
                                                  2024-08-28 13:35:38 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                                                  Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                                                  2024-08-28 13:35:38 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                                                  Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro

                                                  Click to jump to process

                                                  Click to jump to process

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:09:34:50
                                                  Start date:28/08/2024
                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\PaymentOnline.html"
                                                  File size:3'242'272 bytes
                                                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:false

                                                  Target ID:2
                                                  Start time:09:34:52
                                                  Start date:28/08/2024
                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2008,i,10137650121201936708,14751184556041639990,262144 /prefetch:8
                                                  File size:3'242'272 bytes
                                                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:false

                                                  No disassembly