Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.rb.gy/xe87a0/

Overview

General Information

Sample URL:http://www.rb.gy/xe87a0/
Analysis ID:1520914
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 2344 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,7574924325276119961,4022375500511274306,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6288 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/xe87a0/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.rb.gy/xe87a0/SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: https://dev-493593595923052ii3200.pantheonsite.io/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dev-493593595923052ii3200.pantheonsite.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dev-493593595923052ii3200.pantheonsite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dev-493593595923052ii3200.pantheonsite.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /xe87a0/ HTTP/1.1Host: www.rb.gyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.rb.gy
Source: global trafficDNS traffic detected: DNS query: dev-493593595923052ii3200.pantheonsite.io
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/4@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,7574924325276119961,4022375500511274306,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/xe87a0/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,7574924325276119961,4022375500511274306,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.rb.gy/xe87a0/100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
fe4.edge.pantheon.io
23.185.0.4
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      142.250.185.132
      truefalse
        unknown
        www.rb.gy
        44.197.136.35
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            unknown
            dev-493593595923052ii3200.pantheonsite.io
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://dev-493593595923052ii3200.pantheonsite.io/false
                unknown
                http://www.rb.gy/xe87a0/true
                  unknown
                  https://dev-493593595923052ii3200.pantheonsite.io/favicon.icofalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    44.197.136.35
                    www.rb.gyUnited States
                    14618AMAZON-AESUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    23.185.0.4
                    fe4.edge.pantheon.ioUnited States
                    54113FASTLYUSfalse
                    142.250.185.132
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    192.168.2.5
                    Joe Sandbox version:41.0.0 Charoite
                    Analysis ID:1520914
                    Start date and time:2024-09-28 01:34:59 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 6s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://www.rb.gy/xe87a0/
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal48.win@17/4@6/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 66.102.1.84, 142.250.186.163, 216.58.206.78, 34.104.35.123, 20.114.59.183, 199.232.210.172, 192.229.221.95, 13.85.23.206, 40.69.42.241, 216.58.206.67
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://www.rb.gy/xe87a0/
                    No simulations
                    InputOutput
                    URL: https://dev-493593595923052ii3200.pantheonsite.io/ Model: jbxai
                    {
                    "brand":[],
                    "contains_trigger_text":false,
                    "trigger_text":"",
                    "prominent_button_name":"unknown",
                    "text_input_field_labels":"unknown",
                    "pdf_icon_visible":false,
                    "has_visible_captcha":false,
                    "has_urgent_text":false,
                    "has_visible_qrcode":false}
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:downloaded
                    Size (bytes):616
                    Entropy (8bit):4.562595923555264
                    Encrypted:false
                    SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
                    MD5:98DD13B362E5AFD02246C08839DB3122
                    SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
                    SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
                    SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
                    Malicious:false
                    Reputation:low
                    URL:https://dev-493593595923052ii3200.pantheonsite.io/favicon.ico
                    Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text
                    Category:downloaded
                    Size (bytes):616
                    Entropy (8bit):4.562595923555264
                    Encrypted:false
                    SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
                    MD5:98DD13B362E5AFD02246C08839DB3122
                    SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
                    SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
                    SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
                    Malicious:false
                    Reputation:low
                    URL:https://dev-493593595923052ii3200.pantheonsite.io/
                    Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Sep 28, 2024 01:35:44.444475889 CEST49675443192.168.2.4173.222.162.32
                    Sep 28, 2024 01:35:54.053751945 CEST49675443192.168.2.4173.222.162.32
                    Sep 28, 2024 01:35:56.659615040 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:56.660214901 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:56.665869951 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:35:56.665952921 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:56.666099072 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:56.666310072 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:35:56.666383982 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:56.671504974 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:35:57.141011953 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:35:57.214107037 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.214196920 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.214323044 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.214576006 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.214610100 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.349594116 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:35:57.349719048 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:35:57.697830915 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.702682018 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.702733994 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.704336882 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.704431057 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.714948893 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.715104103 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.715589046 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.715624094 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.758393049 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.834692001 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.835247993 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:57.835350037 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.877173901 CEST49737443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:57.877218008 CEST4434973723.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.000349045 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.000452995 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.000530958 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.001295090 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.001331091 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.493217945 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.542175055 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.548605919 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.548619032 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.549314022 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.555053949 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.555159092 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.555737972 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.599442959 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.684856892 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.685410976 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:58.685487986 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.694695950 CEST49739443192.168.2.423.185.0.4
                    Sep 28, 2024 01:35:58.694731951 CEST4434973923.185.0.4192.168.2.4
                    Sep 28, 2024 01:35:59.262828112 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:35:59.262876987 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:35:59.262948036 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:35:59.264669895 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:35:59.264691114 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:35:59.903717995 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:35:59.958359003 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.026436090 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.026452065 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:00.027975082 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:00.027991056 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:00.028070927 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.029617071 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.029782057 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:00.083332062 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.083359003 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:00.130218983 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:00.730416059 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:00.730468988 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:00.730618000 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:00.732702971 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:00.732731104 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.091372967 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.091465950 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.099931955 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.099956989 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.100220919 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.149074078 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.177771091 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.219409943 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.380219936 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.380297899 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.380352974 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.380500078 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.380525112 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.380536079 CEST49742443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.380542040 CEST44349742184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.435187101 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.435226917 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:02.435340881 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.435745001 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:02.435770988 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.321352959 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.321470976 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.323678970 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.323689938 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.324012995 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.325151920 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.371398926 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.601890087 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.601984978 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.602039099 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.602960110 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.602960110 CEST49743443192.168.2.4184.28.90.27
                    Sep 28, 2024 01:36:03.602981091 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:03.602996111 CEST44349743184.28.90.27192.168.2.4
                    Sep 28, 2024 01:36:09.809357882 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:09.809449911 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:09.809592009 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:09.869963884 CEST49741443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:09.870009899 CEST44349741142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:41.673578978 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:41.682173014 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:42.142237902 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:42.284668922 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:57.074269056 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:57.074331999 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:57.145334005 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:57.145420074 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:57.760077000 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:57.760082960 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.068110943 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.068126917 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.677474022 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.677504063 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.703341961 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703356981 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703365088 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703381062 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703396082 CEST804973644.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703403950 CEST804973544.197.136.35192.168.2.4
                    Sep 28, 2024 01:36:58.703421116 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.703455925 CEST4973680192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.703450918 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:58.703450918 CEST4973580192.168.2.444.197.136.35
                    Sep 28, 2024 01:36:59.298470974 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:59.298515081 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:36:59.298578978 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:59.299473047 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:36:59.299488068 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:00.373732090 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:00.374285936 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:37:00.374315023 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:00.374641895 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:00.375294924 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:37:00.375356913 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:00.427468061 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:37:09.850723982 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:09.850780964 CEST44349752142.250.185.132192.168.2.4
                    Sep 28, 2024 01:37:09.850852013 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:37:11.758759975 CEST49752443192.168.2.4142.250.185.132
                    Sep 28, 2024 01:37:11.758790016 CEST44349752142.250.185.132192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Sep 28, 2024 01:35:55.554692984 CEST53628231.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:55.554703951 CEST53631141.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:56.645662069 CEST5520753192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:56.645843983 CEST5820353192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:56.656048059 CEST53582031.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:56.656783104 CEST53552071.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:56.670814991 CEST53640461.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:57.143959045 CEST5322653192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:57.144171000 CEST6404253192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:57.176264048 CEST53640421.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:57.187562943 CEST53532261.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:59.248100042 CEST5643653192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:59.248868942 CEST5377653192.168.2.41.1.1.1
                    Sep 28, 2024 01:35:59.254792929 CEST53564361.1.1.1192.168.2.4
                    Sep 28, 2024 01:35:59.255665064 CEST53537761.1.1.1192.168.2.4
                    Sep 28, 2024 01:36:11.796935081 CEST138138192.168.2.4192.168.2.255
                    Sep 28, 2024 01:36:13.639710903 CEST53534751.1.1.1192.168.2.4
                    Sep 28, 2024 01:36:32.662820101 CEST53580981.1.1.1192.168.2.4
                    Sep 28, 2024 01:36:55.169492006 CEST53649101.1.1.1192.168.2.4
                    Sep 28, 2024 01:36:55.173111916 CEST53520601.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Sep 28, 2024 01:35:56.645662069 CEST192.168.2.41.1.1.10x2894Standard query (0)www.rb.gyA (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:56.645843983 CEST192.168.2.41.1.1.10xb716Standard query (0)www.rb.gy65IN (0x0001)false
                    Sep 28, 2024 01:35:57.143959045 CEST192.168.2.41.1.1.10x7b09Standard query (0)dev-493593595923052ii3200.pantheonsite.ioA (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:57.144171000 CEST192.168.2.41.1.1.10x8983Standard query (0)dev-493593595923052ii3200.pantheonsite.io65IN (0x0001)false
                    Sep 28, 2024 01:35:59.248100042 CEST192.168.2.41.1.1.10x8bc5Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:59.248868942 CEST192.168.2.41.1.1.10x6703Standard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Sep 28, 2024 01:35:56.656783104 CEST1.1.1.1192.168.2.40x2894No error (0)www.rb.gy44.197.136.35A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:56.656783104 CEST1.1.1.1192.168.2.40x2894No error (0)www.rb.gy44.193.97.228A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:56.656783104 CEST1.1.1.1192.168.2.40x2894No error (0)www.rb.gy54.236.142.223A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:57.176264048 CEST1.1.1.1192.168.2.40x8983No error (0)dev-493593595923052ii3200.pantheonsite.iofe4.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:35:57.187562943 CEST1.1.1.1192.168.2.40x7b09No error (0)dev-493593595923052ii3200.pantheonsite.iofe4.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:35:57.187562943 CEST1.1.1.1192.168.2.40x7b09No error (0)fe4.edge.pantheon.io23.185.0.4A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:59.254792929 CEST1.1.1.1192.168.2.40x8bc5No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:35:59.255665064 CEST1.1.1.1192.168.2.40x6703No error (0)www.google.com65IN (0x0001)false
                    Sep 28, 2024 01:36:07.544434071 CEST1.1.1.1192.168.2.40x875cNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:36:07.544434071 CEST1.1.1.1192.168.2.40x875cNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:36:08.929075003 CEST1.1.1.1192.168.2.40xbae9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:36:08.929075003 CEST1.1.1.1192.168.2.40xbae9No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:36:21.216919899 CEST1.1.1.1192.168.2.40x6f81No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:36:21.216919899 CEST1.1.1.1192.168.2.40x6f81No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:36:47.744009972 CEST1.1.1.1192.168.2.40xe2acNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:36:47.744009972 CEST1.1.1.1192.168.2.40xe2acNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    Sep 28, 2024 01:37:08.418107033 CEST1.1.1.1192.168.2.40x9cf9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Sep 28, 2024 01:37:08.418107033 CEST1.1.1.1192.168.2.40x9cf9No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                    • dev-493593595923052ii3200.pantheonsite.io
                    • https:
                    • fs.microsoft.com
                    • www.rb.gy
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44973544.197.136.35803848C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Sep 28, 2024 01:35:56.666099072 CEST431OUTGET /xe87a0/ HTTP/1.1
                    Host: www.rb.gy
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Sep 28, 2024 01:35:57.141011953 CEST265INHTTP/1.1 301 Moved Permanently
                    Date: Fri, 27 Sep 2024 23:35:57 GMT
                    Content-Length: 0
                    Connection: keep-alive
                    Cache-Control: no-cache, no-store
                    Expires: -1
                    Location: https://dev-493593595923052ii3200.pantheonsite.io/
                    Engine: Rebrandly.redirect, version 2.1
                    Sep 28, 2024 01:35:57.349594116 CEST265INHTTP/1.1 301 Moved Permanently
                    Date: Fri, 27 Sep 2024 23:35:57 GMT
                    Content-Length: 0
                    Connection: keep-alive
                    Cache-Control: no-cache, no-store
                    Expires: -1
                    Location: https://dev-493593595923052ii3200.pantheonsite.io/
                    Engine: Rebrandly.redirect, version 2.1
                    Sep 28, 2024 01:36:42.142237902 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44973644.197.136.35803848C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Sep 28, 2024 01:36:41.673578978 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44973723.185.0.44433848C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-09-27 23:35:57 UTC684OUTGET / HTTP/1.1
                    Host: dev-493593595923052ii3200.pantheonsite.io
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-09-27 23:35:57 UTC560INHTTP/1.1 504 Target in maintenance
                    Connection: close
                    Content-Length: 616
                    Retry-After: 0
                    X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
                    Content-Type: text/html; charset=utf-8
                    Fastly-Restarts: 1
                    Date: Fri, 27 Sep 2024 23:35:57 GMT
                    Server: Pantheon
                    X-Served-By: cache-chi-kigq8000086-CHI, cache-ewr-kewr1740035-EWR
                    X-Cache: MISS, MISS
                    X-Cache-Hits: 0, 0
                    X-Timer: S1727480158.765191,VS0,VE25
                    Vary: Cookie, Cookie
                    X-Robots-Tag: noindex
                    Age: 0
                    Accept-Ranges: bytes
                    Via: 1.1 varnish, 1.1 varnish
                    2024-09-27 23:35:57 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                    Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44973923.185.0.44433848C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-09-27 23:35:58 UTC638OUTGET /favicon.ico HTTP/1.1
                    Host: dev-493593595923052ii3200.pantheonsite.io
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://dev-493593595923052ii3200.pantheonsite.io/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-09-27 23:35:58 UTC560INHTTP/1.1 504 Target in maintenance
                    Connection: close
                    Content-Length: 616
                    Retry-After: 0
                    X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
                    Content-Type: text/html; charset=utf-8
                    Fastly-Restarts: 1
                    Date: Fri, 27 Sep 2024 23:35:58 GMT
                    Server: Pantheon
                    X-Served-By: cache-chi-klot8100114-CHI, cache-ewr-kewr1740037-EWR
                    X-Cache: MISS, MISS
                    X-Cache-Hits: 0, 0
                    X-Timer: S1727480159.605557,VS0,VE28
                    Vary: Cookie, Cookie
                    X-Robots-Tag: noindex
                    Age: 0
                    Accept-Ranges: bytes
                    Via: 1.1 varnish, 1.1 varnish
                    2024-09-27 23:35:58 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                    Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449742184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-09-27 23:36:02 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-09-27 23:36:02 UTC467INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF67)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-neu-z1
                    Cache-Control: public, max-age=234540
                    Date: Fri, 27 Sep 2024 23:36:02 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449743184.28.90.27443
                    TimestampBytes transferredDirectionData
                    2024-09-27 23:36:03 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-09-27 23:36:03 UTC515INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (lpl/EF06)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-weu-z1
                    Cache-Control: public, max-age=234569
                    Date: Fri, 27 Sep 2024 23:36:03 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-09-27 23:36:03 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:19:35:48
                    Start date:27/09/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:19:35:53
                    Start date:27/09/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2012,i,7574924325276119961,4022375500511274306,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:19:35:55
                    Start date:27/09/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.rb.gy/xe87a0/"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly