Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://gemini-l_ogin.godaddysites.com/

Overview

General Information

Sample URL:https://gemini-l_ogin.godaddysites.com/
Analysis ID:1521116
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6088 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4448 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=2004,i,14736410055273814364,3190996273331780647,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3032 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-l_ogin.godaddysites.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://gemini-l_ogin.godaddysites.com/SlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering
Source: gemini-l_ogin.godaddysites.comVirustotal: Detection: 11%Perma Link
Source: https://gemini-l_ogin.godaddysites.com/Virustotal: Detection: 6%Perma Link
Source: https://gemini-l_ogin.godaddysites.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49725 version: TLS 1.0
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.5:52452 -> 162.159.36.2:53
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49725 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: gemini-l_ogin.godaddysites.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: gemini-l_ogin.godaddysites.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://gemini-l_ogin.godaddysites.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dps_site_id=us-east-1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: gemini-l_ogin.godaddysites.com
Source: global trafficDNS traffic detected: DNS query: img1.wsimg.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: 198.187.3.20.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html;charset=utf-8Content-Length: 964Vary: Accept-EncodingServer: DPS/2.0.0+sha-227ca78X-Version: 227ca78X-SiteId: us-east-1Set-Cookie: dps_site_id=us-east-1; path=/; secureDate: Sat, 28 Sep 2024 02:32:37 GMTConnection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html;charset=utf-8Content-Length: 964Vary: Accept-EncodingServer: DPS/2.0.0+sha-227ca78X-Version: 227ca78X-SiteId: us-east-1Set-Cookie: dps_site_id=us-east-1; path=/; secureDate: Sat, 28 Sep 2024 02:32:39 GMTConnection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52458
Source: unknownNetwork traffic detected: HTTP traffic on port 52458 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: classification engineClassification label: mal64.win@16/10@8/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=2004,i,14736410055273814364,3190996273331780647,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-l_ogin.godaddysites.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=2004,i,14736410055273814364,3190996273331780647,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://gemini-l_ogin.godaddysites.com/6%VirustotalBrowse
https://gemini-l_ogin.godaddysites.com/100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
198.187.3.20.in-addr.arpa1%VirustotalBrowse
gemini-l_ogin.godaddysites.com11%VirustotalBrowse
www.google.com0%VirustotalBrowse
img1.wsimg.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
gemini-l_ogin.godaddysites.com
13.248.243.5
truefalseunknown
www.google.com
142.250.185.164
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
img1.wsimg.com
unknown
unknownfalseunknown
198.187.3.20.in-addr.arpa
unknown
unknownfalseunknown
NameMaliciousAntivirus DetectionReputation
https://gemini-l_ogin.godaddysites.com/true
    unknown
    https://gemini-l_ogin.godaddysites.com/favicon.icotrue
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      142.250.184.196
      unknownUnited States
      15169GOOGLEUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.185.164
      www.google.comUnited States
      15169GOOGLEUSfalse
      13.248.243.5
      gemini-l_ogin.godaddysites.comUnited States
      16509AMAZON-02USfalse
      IP
      192.168.2.6
      192.168.2.5
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1521116
      Start date and time:2024-09-28 04:31:41 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 17s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://gemini-l_ogin.godaddysites.com/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal64.win@16/10@8/6
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.181.238, 74.125.133.84, 34.104.35.123, 23.38.98.114, 23.38.98.78, 4.245.163.56, 199.232.210.172, 192.229.221.95, 20.3.187.198, 13.95.31.18, 52.165.165.26, 131.107.255.255, 20.114.59.183, 216.58.206.67, 199.232.214.172
      • Excluded domains from analysis (whitelisted): e40258.g.akamaiedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, global-wildcard.wsimg.com.sni-only.edgekey.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      InputOutput
      URL: https://gemini-l_ogin.godaddysites.com/ Model: jbxai
      {
      "brand":[],
      "contains_trigger_text":false,
      "trigger_text":"",
      "prominent_button_name":"unknown",
      "text_input_field_labels":"unknown",
      "pdf_icon_visible":false,
      "has_visible_captcha":false,
      "has_urgent_text":false,
      "has_visible_qrcode":false}
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 01:32:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.978548581229149
      Encrypted:false
      SSDEEP:48:8VodEQTk09bNHiidAKZdA19ehwiZUklqehiy+3:8V1QIcbmpy
      MD5:7ED5D9F7DD1E8C96D4B0B86DA31E1ABB
      SHA1:82BC39ADB7242571DA7FE6C2083C6F1AA086C788
      SHA-256:6DA74BD9A89812164F41A8CBB812C8C656FD34E477FEFFFE9E1FEBDF4356FF7F
      SHA-512:655A372CD1DE18106B3F9B3E6792EFC20CF29D8EB28B88E28378EDE1FD25861D3043E2B54952AE0E48B1C7C61FB5478A9F04EECE13AA29850EEF1CA423835B01
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....;.0.N...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 01:32:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):3.992380741158205
      Encrypted:false
      SSDEEP:48:86odEQTk09bNHiidAKZdA1weh/iZUkAQkqehZy+2:861QIcbk9Qsy
      MD5:3D80BF942775DBF2A8C3E8F2B2B6DA1C
      SHA1:53E339516D0CC8BAF768E4C2C1B9D880578619B1
      SHA-256:7D1E175282B873D83F82FDB52175CC42BC0D35FCAC29F664D28840C33DA48DA9
      SHA-512:BB09059628735547A0A41B48B39C4B0D4693A47A9E6BCCA09CEB8C6AB247EE5D9517621E2E911D80FF8BCC6285F9A987E47FF2053F4EE23DE6E13538B51B2A29
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,.....i$.N...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2693
      Entropy (8bit):4.006620701036727
      Encrypted:false
      SSDEEP:48:8x5odEQTk09bsHiidAKZdA14tseh7sFiZUkmgqeh7sLy+BX:8x51QIcb7ndy
      MD5:2B806C18C5864B54EE7764088780F1CD
      SHA1:ACB698869FA0FC1167A118DA9661606A4895840F
      SHA-256:E40E2141D03657109643F4CE31357A4390DF567647409ABAC9A68D97211F0A13
      SHA-512:5032D746DFC2B1AB24A07557CFDB6594EB688C8686ACAE69E353F07390CDF4413EB002E7C4E3AA2A01A1CB9B2A14C72BB3C3314722851CAD4A50E55E40D25BC6
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 01:32:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9955501662160557
      Encrypted:false
      SSDEEP:48:85odEQTk09bNHiidAKZdA1vehDiZUkwqehFy+R:851QIcbvTy
      MD5:2DD3574E880F7B76C951D24485E68960
      SHA1:81C177792098A681F3AFD47191A3E38CC7DC45E8
      SHA-256:707AE7EB1BEF9E8DA5CD84AE8AC1061F40D9A63E2E3BDB92D9CED6EE5E6FBCCC
      SHA-512:414E0CF1EE2D3DA5E5C078432043DB0229BA6599C197B685E9CB1F7078D667619E30BC3EA769D818CA186557275329BA7B0708013C41AA35BA73F68C67DDB365
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,........N...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 01:32:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9813290610225125
      Encrypted:false
      SSDEEP:48:8YodEQTk09bNHiidAKZdA1hehBiZUk1W1qehPy+C:8Y1QIcbP9vy
      MD5:2C71A1B39689B0AE8E8E9A4F642CEE9F
      SHA1:729F88A99F5E0F83E1F766B86275F4DE65224141
      SHA-256:894B06854D7408A43804F5321965E96A3545AEFC474C7F800F5EF36FA84DB212
      SHA-512:0A8EBE4F13CC5F0A907F46A0F4E112368DC2FCAB28E6BF8E304243DBBBCF8E75DEC821AA7FDF630DEBA45AC9E700CBDFFCA4B4AE0C4EE7CA6D663D3AB869C89F
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,.....k+.N...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 01:32:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2683
      Entropy (8bit):3.9894099481419087
      Encrypted:false
      SSDEEP:48:8KKodEQTk09bNHiidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbdy+yT+:871QIcbHT/TbxWOvTbdy7T
      MD5:624F0F7ED821B9FBA9C0D7A159AC97A5
      SHA1:8D56466B8C2B04A66F110DD25F90F0015A646D2C
      SHA-256:45FFF316C89983449338970BEBF20EB1F44025CECDF6EF78BCFE721BBC2533B0
      SHA-512:ECD0C531D3CA9FE37009C9C86ABD4ACB16E9536E45915EE1591BFEC76BF8B1BBB071A4BE2A6A178FC6E3D3CE7BADE09F22B25C5831A5EDE002624A6D7D750EAB
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,........N...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Dt|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text
      Category:downloaded
      Size (bytes):964
      Entropy (8bit):4.838435923338608
      Encrypted:false
      SSDEEP:24:hYfeRJspxwCxykxKon1xJRvey836x/CWHOFqV2g:Ae8pHlxX1xJRvB834Cw/
      MD5:A0F191E36F48B24420FA1A51A42A91D1
      SHA1:947DA7A79DCFAE9B6811D2FC42F0BD510A1D5533
      SHA-256:5C789BF141C0262059DB82230F158B698AD8D835760E4D2A46D2C50524CEEDA2
      SHA-512:FD72C0EEF46869126E996FA7E5260EE682C4CDDF1C83E877A34B548ED25853887B611FB1C7F8B84D3F8CC59158E78FE4310F52B1FC75BBE164764F35E6C32250
      Malicious:false
      Reputation:low
      URL:https://gemini-l_ogin.godaddysites.com/
      Preview:<!DOCTYPE html>.<html>.<head>. <title>404 Not Found</title>. <meta http-equiv="content-type" content="text/html; charset=utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <link href="//img1.wsimg.com/dps/css/uxcore.css" rel="stylesheet">. <link href="//img1.wsimg.com/dps/css/customer-comp.css" rel="stylesheet">.</head>..<body>.<div id="error-img"><img src="//img1.wsimg.com/dps/images/404_background.jpg"></div>.<div class="container text-center" id="error">. <div class="row">. <div class="col-md-12">. <div class="main-icon text-warning"><span class="uxicon uxicon-alert"></span></div>. <h1>File not found (404 error)</h1>. </div>. </div>. <div class="row">. <div class="col-md-6 col-md-push-3">. <p class="lead">If you think what you're looking for should be here, please contact the site owner.</p>. </div>. </div>.</div>..</body>.</html>.
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text
      Category:downloaded
      Size (bytes):964
      Entropy (8bit):4.838435923338608
      Encrypted:false
      SSDEEP:24:hYfeRJspxwCxykxKon1xJRvey836x/CWHOFqV2g:Ae8pHlxX1xJRvB834Cw/
      MD5:A0F191E36F48B24420FA1A51A42A91D1
      SHA1:947DA7A79DCFAE9B6811D2FC42F0BD510A1D5533
      SHA-256:5C789BF141C0262059DB82230F158B698AD8D835760E4D2A46D2C50524CEEDA2
      SHA-512:FD72C0EEF46869126E996FA7E5260EE682C4CDDF1C83E877A34B548ED25853887B611FB1C7F8B84D3F8CC59158E78FE4310F52B1FC75BBE164764F35E6C32250
      Malicious:false
      Reputation:low
      URL:https://gemini-l_ogin.godaddysites.com/favicon.ico
      Preview:<!DOCTYPE html>.<html>.<head>. <title>404 Not Found</title>. <meta http-equiv="content-type" content="text/html; charset=utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <link href="//img1.wsimg.com/dps/css/uxcore.css" rel="stylesheet">. <link href="//img1.wsimg.com/dps/css/customer-comp.css" rel="stylesheet">.</head>..<body>.<div id="error-img"><img src="//img1.wsimg.com/dps/images/404_background.jpg"></div>.<div class="container text-center" id="error">. <div class="row">. <div class="col-md-12">. <div class="main-icon text-warning"><span class="uxicon uxicon-alert"></span></div>. <h1>File not found (404 error)</h1>. </div>. </div>. <div class="row">. <div class="col-md-6 col-md-push-3">. <p class="lead">If you think what you're looking for should be here, please contact the site owner.</p>. </div>. </div>.</div>..</body>.</html>.
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Sep 28, 2024 04:32:28.284281969 CEST49675443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:28.284286976 CEST49674443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:28.393691063 CEST49673443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:36.677459002 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.677544117 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:36.677584887 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.677622080 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:36.677644968 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.677735090 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.678494930 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.678519011 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:36.679137945 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:36.679162025 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.151823997 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.153947115 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.153983116 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.154894114 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.154980898 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.155968904 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.156035900 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.156187057 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.156203985 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.175817013 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.176074982 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.176091909 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.177167892 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.177239895 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.177575111 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.177644968 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.276055098 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.292154074 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.292179108 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.337275982 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.337420940 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.337481022 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.339997053 CEST49710443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.340028048 CEST4434971013.248.243.5192.168.2.5
      Sep 28, 2024 04:32:37.481005907 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:37.888827085 CEST49674443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:37.979280949 CEST49675443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:38.088980913 CEST49673443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:39.189493895 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:39.235403061 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:39.297363043 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:39.297446012 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:39.297542095 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:39.298815012 CEST49709443192.168.2.513.248.243.5
      Sep 28, 2024 04:32:39.298862934 CEST4434970913.248.243.5192.168.2.5
      Sep 28, 2024 04:32:39.646651983 CEST4434970323.1.237.91192.168.2.5
      Sep 28, 2024 04:32:39.646743059 CEST49703443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:39.833741903 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:39.833800077 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:39.833995104 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:39.834294081 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:39.834305048 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.493510008 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.539493084 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.571336031 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.571366072 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.572472095 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.572551966 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.660227060 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.660322905 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.711355925 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.711402893 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:40.758228064 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:40.936249971 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:40.936296940 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:40.936362982 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:40.938736916 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:40.938746929 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.595652103 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.595738888 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:41.645700932 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:41.645737886 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.646035910 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.696337938 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:41.790015936 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:41.835408926 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.978950024 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.979027033 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:41.979079962 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.032826900 CEST49717443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.032860994 CEST44349717184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.343110085 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.343166113 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.343228102 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.343775034 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.343796968 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.975182056 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.975263119 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.976524115 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:42.976545095 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.976777077 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:42.977989912 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:43.023395061 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:43.250508070 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:43.250576973 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:43.250639915 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:43.253496885 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:43.253521919 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:43.253551006 CEST49718443192.168.2.5184.28.90.27
      Sep 28, 2024 04:32:43.253557920 CEST44349718184.28.90.27192.168.2.5
      Sep 28, 2024 04:32:50.523966074 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:50.524032116 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:32:50.524101973 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:50.698174953 CEST49703443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:50.698252916 CEST49703443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:50.700134993 CEST49725443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:50.700174093 CEST4434972523.1.237.91192.168.2.5
      Sep 28, 2024 04:32:50.700253963 CEST49725443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:50.701780081 CEST49725443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:50.701796055 CEST4434972523.1.237.91192.168.2.5
      Sep 28, 2024 04:32:50.703115940 CEST4434970323.1.237.91192.168.2.5
      Sep 28, 2024 04:32:50.703150034 CEST4434970323.1.237.91192.168.2.5
      Sep 28, 2024 04:32:51.293521881 CEST4434972523.1.237.91192.168.2.5
      Sep 28, 2024 04:32:51.293592930 CEST49725443192.168.2.523.1.237.91
      Sep 28, 2024 04:32:51.637379885 CEST49716443192.168.2.5142.250.185.164
      Sep 28, 2024 04:32:51.637425900 CEST44349716142.250.185.164192.168.2.5
      Sep 28, 2024 04:33:05.313043118 CEST5245253192.168.2.5162.159.36.2
      Sep 28, 2024 04:33:05.317899942 CEST5352452162.159.36.2192.168.2.5
      Sep 28, 2024 04:33:05.317996025 CEST5245253192.168.2.5162.159.36.2
      Sep 28, 2024 04:33:05.318048954 CEST5245253192.168.2.5162.159.36.2
      Sep 28, 2024 04:33:05.322807074 CEST5352452162.159.36.2192.168.2.5
      Sep 28, 2024 04:33:05.761111021 CEST5352452162.159.36.2192.168.2.5
      Sep 28, 2024 04:33:05.762449980 CEST5245253192.168.2.5162.159.36.2
      Sep 28, 2024 04:33:05.767617941 CEST5352452162.159.36.2192.168.2.5
      Sep 28, 2024 04:33:05.767715931 CEST5245253192.168.2.5162.159.36.2
      Sep 28, 2024 04:33:10.455789089 CEST4434972523.1.237.91192.168.2.5
      Sep 28, 2024 04:33:10.455862045 CEST49725443192.168.2.523.1.237.91
      Sep 28, 2024 04:33:39.878334999 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:39.878369093 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:39.878528118 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:39.878737926 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:39.878751040 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:40.508074999 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:40.508424044 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:40.508446932 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:40.508912086 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:40.509246111 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:40.509324074 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:40.555723906 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:50.424573898 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:50.424645901 CEST44352458142.250.184.196192.168.2.5
      Sep 28, 2024 04:33:50.424709082 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:51.661581039 CEST52458443192.168.2.5142.250.184.196
      Sep 28, 2024 04:33:51.661626101 CEST44352458142.250.184.196192.168.2.5
      TimestampSource PortDest PortSource IPDest IP
      Sep 28, 2024 04:32:35.398807049 CEST53504241.1.1.1192.168.2.5
      Sep 28, 2024 04:32:35.444395065 CEST53535371.1.1.1192.168.2.5
      Sep 28, 2024 04:32:36.577497005 CEST53610091.1.1.1192.168.2.5
      Sep 28, 2024 04:32:36.668569088 CEST4934553192.168.2.51.1.1.1
      Sep 28, 2024 04:32:36.668862104 CEST5984353192.168.2.51.1.1.1
      Sep 28, 2024 04:32:36.676337004 CEST53598431.1.1.1192.168.2.5
      Sep 28, 2024 04:32:36.676639080 CEST53493451.1.1.1192.168.2.5
      Sep 28, 2024 04:32:37.354614973 CEST5566253192.168.2.51.1.1.1
      Sep 28, 2024 04:32:37.354784966 CEST6392653192.168.2.51.1.1.1
      Sep 28, 2024 04:32:39.822799921 CEST6222753192.168.2.51.1.1.1
      Sep 28, 2024 04:32:39.823950052 CEST5930853192.168.2.51.1.1.1
      Sep 28, 2024 04:32:39.829360008 CEST53622271.1.1.1192.168.2.5
      Sep 28, 2024 04:32:39.830488920 CEST53593081.1.1.1192.168.2.5
      Sep 28, 2024 04:32:53.552354097 CEST53596791.1.1.1192.168.2.5
      Sep 28, 2024 04:33:05.312558889 CEST5355670162.159.36.2192.168.2.5
      Sep 28, 2024 04:33:05.811347008 CEST6501553192.168.2.51.1.1.1
      Sep 28, 2024 04:33:05.818650007 CEST53650151.1.1.1192.168.2.5
      Sep 28, 2024 04:33:39.870636940 CEST5992753192.168.2.51.1.1.1
      Sep 28, 2024 04:33:39.877157927 CEST53599271.1.1.1192.168.2.5
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Sep 28, 2024 04:32:36.668569088 CEST192.168.2.51.1.1.10xf8adStandard query (0)gemini-l_ogin.godaddysites.comA (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:36.668862104 CEST192.168.2.51.1.1.10x11c9Standard query (0)gemini-l_ogin.godaddysites.com65IN (0x0001)false
      Sep 28, 2024 04:32:37.354614973 CEST192.168.2.51.1.1.10x8cdeStandard query (0)img1.wsimg.comA (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:37.354784966 CEST192.168.2.51.1.1.10x3d5eStandard query (0)img1.wsimg.com65IN (0x0001)false
      Sep 28, 2024 04:32:39.822799921 CEST192.168.2.51.1.1.10x9086Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:39.823950052 CEST192.168.2.51.1.1.10x55c7Standard query (0)www.google.com65IN (0x0001)false
      Sep 28, 2024 04:33:05.811347008 CEST192.168.2.51.1.1.10xa948Standard query (0)198.187.3.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
      Sep 28, 2024 04:33:39.870636940 CEST192.168.2.51.1.1.10x4a81Standard query (0)www.google.comA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Sep 28, 2024 04:32:36.676639080 CEST1.1.1.1192.168.2.50xf8adNo error (0)gemini-l_ogin.godaddysites.com13.248.243.5A (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:36.676639080 CEST1.1.1.1192.168.2.50xf8adNo error (0)gemini-l_ogin.godaddysites.com76.223.105.230A (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:37.362238884 CEST1.1.1.1192.168.2.50x3d5eNo error (0)img1.wsimg.comglobal-wildcard.wsimg.com.sni-only.edgekey.netCNAME (Canonical name)IN (0x0001)false
      Sep 28, 2024 04:32:37.362581968 CEST1.1.1.1192.168.2.50x8cdeNo error (0)img1.wsimg.comglobal-wildcard.wsimg.com.sni-only.edgekey.netCNAME (Canonical name)IN (0x0001)false
      Sep 28, 2024 04:32:39.829360008 CEST1.1.1.1192.168.2.50x9086No error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:39.830488920 CEST1.1.1.1192.168.2.50x55c7No error (0)www.google.com65IN (0x0001)false
      Sep 28, 2024 04:32:49.529346943 CEST1.1.1.1192.168.2.50x2b6eNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:49.529346943 CEST1.1.1.1192.168.2.50x2b6eNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Sep 28, 2024 04:32:50.026788950 CEST1.1.1.1192.168.2.50x53e4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 28, 2024 04:32:50.026788950 CEST1.1.1.1192.168.2.50x53e4No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 28, 2024 04:33:03.297393084 CEST1.1.1.1192.168.2.50x6710No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 28, 2024 04:33:03.297393084 CEST1.1.1.1192.168.2.50x6710No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 28, 2024 04:33:05.818650007 CEST1.1.1.1192.168.2.50xa948Name error (3)198.187.3.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
      Sep 28, 2024 04:33:39.877157927 CEST1.1.1.1192.168.2.50x4a81No error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
      Sep 28, 2024 04:33:50.887703896 CEST1.1.1.1192.168.2.50xeb0eNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Sep 28, 2024 04:33:50.887703896 CEST1.1.1.1192.168.2.50xeb0eNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      • gemini-l_ogin.godaddysites.com
      • https:
      • fs.microsoft.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.54971013.248.243.54434448C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-09-28 02:32:37 UTC673OUTGET / HTTP/1.1
      Host: gemini-l_ogin.godaddysites.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-09-28 02:32:37 UTC288INHTTP/1.1 404 Not Found
      Content-Type: text/html;charset=utf-8
      Content-Length: 964
      Vary: Accept-Encoding
      Server: DPS/2.0.0+sha-227ca78
      X-Version: 227ca78
      X-SiteId: us-east-1
      Set-Cookie: dps_site_id=us-east-1; path=/; secure
      Date: Sat, 28 Sep 2024 02:32:37 GMT
      Connection: close
      2024-09-28 02:32:37 UTC964INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 69 6d 67 31 2e 77 73 69 6d 67 2e 63 6f 6d 2f 64 70 73 2f 63 73 73 2f 75 78 63 6f
      Data Ascii: <!DOCTYPE html><html><head> <title>404 Not Found</title> <meta http-equiv="content-type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <link href="//img1.wsimg.com/dps/css/uxco


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.54970913.248.243.54434448C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-09-28 02:32:39 UTC647OUTGET /favicon.ico HTTP/1.1
      Host: gemini-l_ogin.godaddysites.com
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://gemini-l_ogin.godaddysites.com/
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      Cookie: dps_site_id=us-east-1
      2024-09-28 02:32:39 UTC288INHTTP/1.1 404 Not Found
      Content-Type: text/html;charset=utf-8
      Content-Length: 964
      Vary: Accept-Encoding
      Server: DPS/2.0.0+sha-227ca78
      X-Version: 227ca78
      X-SiteId: us-east-1
      Set-Cookie: dps_site_id=us-east-1; path=/; secure
      Date: Sat, 28 Sep 2024 02:32:39 GMT
      Connection: close
      2024-09-28 02:32:39 UTC964INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 69 6d 67 31 2e 77 73 69 6d 67 2e 63 6f 6d 2f 64 70 73 2f 63 73 73 2f 75 78 63 6f
      Data Ascii: <!DOCTYPE html><html><head> <title>404 Not Found</title> <meta http-equiv="content-type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <link href="//img1.wsimg.com/dps/css/uxco


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.549717184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-28 02:32:41 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-28 02:32:41 UTC467INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF67)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-neu-z1
      Cache-Control: public, max-age=223941
      Date: Sat, 28 Sep 2024 02:32:41 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.549718184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-28 02:32:42 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-28 02:32:43 UTC515INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=223969
      Date: Sat, 28 Sep 2024 02:32:43 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-09-28 02:32:43 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:22:32:29
      Start date:27/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:22:32:33
      Start date:27/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=2004,i,14736410055273814364,3190996273331780647,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:22:32:35
      Start date:27/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-l_ogin.godaddysites.com/"
      Imagebase:0x7ff715980000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly