Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://dev-432403949340149124012.pantheonsite.io/

Overview

General Information

Sample URL:https://dev-432403949340149124012.pantheonsite.io/
Analysis ID:1521298
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2148 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2400,i,15705503142056863312,16820904315009918179,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dev-432403949340149124012.pantheonsite.io/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://dev-432403949340149124012.pantheonsite.io/SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: https://dev-432403949340149124012.pantheonsite.io/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:59839 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 2.18.97.153
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dev-432403949340149124012.pantheonsite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dev-432403949340149124012.pantheonsite.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dev-432403949340149124012.pantheonsite.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: dev-432403949340149124012.pantheonsite.io
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 59843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.18.97.153:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2400,i,15705503142056863312,16820904315009918179,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dev-432403949340149124012.pantheonsite.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2400,i,15705503142056863312,16820904315009918179,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://dev-432403949340149124012.pantheonsite.io/100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.132
truefalse
    unknown
    fe2.edge.pantheon.io
    23.185.0.2
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        dev-432403949340149124012.pantheonsite.io
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://dev-432403949340149124012.pantheonsite.io/true
            unknown
            https://dev-432403949340149124012.pantheonsite.io/favicon.icotrue
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              23.185.0.2
              fe2.edge.pantheon.ioUnited States
              54113FASTLYUSfalse
              142.250.186.132
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              192.168.2.5
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1521298
              Start date and time:2024-09-28 07:25:25 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 11s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://dev-432403949340149124012.pantheonsite.io/
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal48.win@16/4@4/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 216.58.206.67, 142.250.186.78, 64.233.167.84, 34.104.35.123, 4.245.163.56, 93.184.221.240, 192.229.221.95, 52.165.164.15, 13.95.31.18, 142.250.186.35
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, d.3.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.8.0.4.0.0.3.0.1.3.0.6.2.ip6.arpa, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://dev-432403949340149124012.pantheonsite.io/
              No simulations
              InputOutput
              URL: https://dev-432403949340149124012.pantheonsite.io/ Model: jbxai
              {
              "brand":["unknown"],
              "contains_trigger_text":false,
              "trigger_text":"",
              "prominent_button_name":"unknown",
              "text_input_field_labels":"unknown",
              "pdf_icon_visible":false,
              "has_visible_captcha":false,
              "has_urgent_text":false,
              "has_visible_qrcode":false}
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):616
              Entropy (8bit):4.562595923555264
              Encrypted:false
              SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
              MD5:98DD13B362E5AFD02246C08839DB3122
              SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
              SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
              SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
              Malicious:false
              Reputation:low
              URL:https://dev-432403949340149124012.pantheonsite.io/
              Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):616
              Entropy (8bit):4.562595923555264
              Encrypted:false
              SSDEEP:12:OeuEdqtFdToqtX2BNMt6EM6ZVqacS6ZOHHL6ZRoovFweLpGXb:OkQtFR3GSMYVVYOHrYdFVqb
              MD5:98DD13B362E5AFD02246C08839DB3122
              SHA1:B59163D9B55FC51EC6960AC3DC48D563CF48FB68
              SHA-256:69B917D897BF5DF25A22496A08BCE0FDA63A027A0B74CB00A2826CC0002A89DC
              SHA-512:921579354ED50BB45B60BD967D440422C97095732E6657792072EA12C469899243D2301A5D0C97D7BB44BC60FD6F151468D8FB530FB14998128AFECD2029D895
              Malicious:false
              Reputation:low
              URL:https://dev-432403949340149124012.pantheonsite.io/favicon.ico
              Preview:<!DOCTYPE HTML>. <html>. <head>. <title>504 - Target in maintenance</title>. </head>. <body style="font-family:Arial, Helvetica, sans-serif; text-align: center">. <div style='padding-block: 180px'>. <h1>. <div style='font-size: 180px; font-weight: 700'>504</div>. <div style='font-size: 24px; font-weight: 700'>Target in maintenance</div>. </h1>. <p style="font-size: 16px; font-weight: 400">The web site you were looking for is currently undergoing maintenance.</p>. </div>. </body>. </html>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Sep 28, 2024 07:26:09.081996918 CEST49675443192.168.2.4173.222.162.32
              Sep 28, 2024 07:26:18.690623045 CEST49675443192.168.2.4173.222.162.32
              Sep 28, 2024 07:26:19.081311941 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.081351042 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.081414938 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.081720114 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.081773996 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.081917048 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.081933022 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.081940889 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.082160950 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.082178116 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.539782047 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.540060043 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.540083885 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.541064978 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.541131020 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.542126894 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.542187929 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.542335033 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.542426109 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.542433023 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.542574883 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.542645931 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.543842077 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.543910027 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.544212103 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.544312954 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.592781067 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.592792034 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.592818022 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.644754887 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.658051968 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.658178091 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.658236980 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.660825968 CEST49735443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.660854101 CEST4434973523.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.725281000 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.767399073 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.866281033 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.866388083 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:19.866460085 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.867268085 CEST49736443192.168.2.423.185.0.2
              Sep 28, 2024 07:26:19.867305994 CEST4434973623.185.0.2192.168.2.4
              Sep 28, 2024 07:26:21.292926073 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:21.292962074 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:21.293056011 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:21.293690920 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:21.293704033 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:21.961292982 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:21.961560011 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:21.961574078 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:21.962531090 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:21.962588072 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:22.166006088 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:22.166207075 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:22.206108093 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:22.206120014 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:22.252923012 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:22.336705923 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:22.336739063 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:22.336807013 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:22.341662884 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:22.341676950 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:22.958648920 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:22.958874941 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:22.970633984 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:22.970659971 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:22.971005917 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.019294977 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.107291937 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.151402950 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.281841040 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.281922102 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.282056093 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.282056093 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.282092094 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.282116890 CEST49740443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.282124043 CEST443497402.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.324340105 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.324400902 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.324937105 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.325090885 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.325107098 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.938875914 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.938955069 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.941813946 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.941847086 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.942163944 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:23.944092989 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:23.991419077 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:24.191875935 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:24.191952944 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:24.192008018 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:24.200057030 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:24.200081110 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:24.200114012 CEST49741443192.168.2.42.18.97.153
              Sep 28, 2024 07:26:24.200124025 CEST443497412.18.97.153192.168.2.4
              Sep 28, 2024 07:26:31.871563911 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:31.871635914 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:26:31.871740103 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:32.025187969 CEST49739443192.168.2.4142.250.186.132
              Sep 28, 2024 07:26:32.025217056 CEST44349739142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:00.011341095 CEST5983953192.168.2.4162.159.36.2
              Sep 28, 2024 07:27:00.016334057 CEST5359839162.159.36.2192.168.2.4
              Sep 28, 2024 07:27:00.016401052 CEST5983953192.168.2.4162.159.36.2
              Sep 28, 2024 07:27:00.016473055 CEST5983953192.168.2.4162.159.36.2
              Sep 28, 2024 07:27:00.021388054 CEST5359839162.159.36.2192.168.2.4
              Sep 28, 2024 07:27:00.464907885 CEST5359839162.159.36.2192.168.2.4
              Sep 28, 2024 07:27:00.465675116 CEST5983953192.168.2.4162.159.36.2
              Sep 28, 2024 07:27:00.471225977 CEST5359839162.159.36.2192.168.2.4
              Sep 28, 2024 07:27:00.471291065 CEST5983953192.168.2.4162.159.36.2
              Sep 28, 2024 07:27:21.334348917 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:21.334387064 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:21.334516048 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:21.335479975 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:21.335498095 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:22.003377914 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:22.003901005 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:22.003915071 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:22.004993916 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:22.005455971 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:22.005626917 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:22.050436020 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:26.269376993 CEST4972380192.168.2.4199.232.214.172
              Sep 28, 2024 07:27:26.269459009 CEST4972480192.168.2.4199.232.214.172
              Sep 28, 2024 07:27:26.274662971 CEST8049723199.232.214.172192.168.2.4
              Sep 28, 2024 07:27:26.274770975 CEST4972380192.168.2.4199.232.214.172
              Sep 28, 2024 07:27:26.274943113 CEST8049724199.232.214.172192.168.2.4
              Sep 28, 2024 07:27:26.275134087 CEST4972480192.168.2.4199.232.214.172
              Sep 28, 2024 07:27:31.896632910 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:31.896701097 CEST44359843142.250.186.132192.168.2.4
              Sep 28, 2024 07:27:31.896768093 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:33.813308001 CEST59843443192.168.2.4142.250.186.132
              Sep 28, 2024 07:27:33.813337088 CEST44359843142.250.186.132192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Sep 28, 2024 07:26:17.651803017 CEST53645541.1.1.1192.168.2.4
              Sep 28, 2024 07:26:17.668332100 CEST53565981.1.1.1192.168.2.4
              Sep 28, 2024 07:26:18.678234100 CEST53518711.1.1.1192.168.2.4
              Sep 28, 2024 07:26:19.043818951 CEST5598753192.168.2.41.1.1.1
              Sep 28, 2024 07:26:19.044058084 CEST6436053192.168.2.41.1.1.1
              Sep 28, 2024 07:26:19.067802906 CEST53643601.1.1.1192.168.2.4
              Sep 28, 2024 07:26:19.078119993 CEST53559871.1.1.1192.168.2.4
              Sep 28, 2024 07:26:21.283432961 CEST5318553192.168.2.41.1.1.1
              Sep 28, 2024 07:26:21.284178019 CEST6322753192.168.2.41.1.1.1
              Sep 28, 2024 07:26:21.290555954 CEST53531851.1.1.1192.168.2.4
              Sep 28, 2024 07:26:21.290704966 CEST53632271.1.1.1192.168.2.4
              Sep 28, 2024 07:26:35.730355024 CEST53544081.1.1.1192.168.2.4
              Sep 28, 2024 07:26:37.846478939 CEST138138192.168.2.4192.168.2.255
              Sep 28, 2024 07:26:54.466413021 CEST53647601.1.1.1192.168.2.4
              Sep 28, 2024 07:27:00.010771990 CEST5359383162.159.36.2192.168.2.4
              Sep 28, 2024 07:27:00.483320951 CEST53495181.1.1.1192.168.2.4
              Sep 28, 2024 07:27:16.855936050 CEST53644341.1.1.1192.168.2.4
              Sep 28, 2024 07:27:16.997965097 CEST53572451.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 28, 2024 07:26:19.043818951 CEST192.168.2.41.1.1.10xc6c8Standard query (0)dev-432403949340149124012.pantheonsite.ioA (IP address)IN (0x0001)false
              Sep 28, 2024 07:26:19.044058084 CEST192.168.2.41.1.1.10x3ec3Standard query (0)dev-432403949340149124012.pantheonsite.io65IN (0x0001)false
              Sep 28, 2024 07:26:21.283432961 CEST192.168.2.41.1.1.10x94bdStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 28, 2024 07:26:21.284178019 CEST192.168.2.41.1.1.10x22dbStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 28, 2024 07:26:19.067802906 CEST1.1.1.1192.168.2.40x3ec3No error (0)dev-432403949340149124012.pantheonsite.iofe2.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:26:19.078119993 CEST1.1.1.1192.168.2.40xc6c8No error (0)dev-432403949340149124012.pantheonsite.iofe2.edge.pantheon.ioCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:26:19.078119993 CEST1.1.1.1192.168.2.40xc6c8No error (0)fe2.edge.pantheon.io23.185.0.2A (IP address)IN (0x0001)false
              Sep 28, 2024 07:26:21.290555954 CEST1.1.1.1192.168.2.40x94bdNo error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
              Sep 28, 2024 07:26:21.290704966 CEST1.1.1.1192.168.2.40x22dbNo error (0)www.google.com65IN (0x0001)false
              Sep 28, 2024 07:26:33.757147074 CEST1.1.1.1192.168.2.40xe5b9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:26:33.757147074 CEST1.1.1.1192.168.2.40xe5b9No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 28, 2024 07:26:46.932898998 CEST1.1.1.1192.168.2.40x25No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:26:46.932898998 CEST1.1.1.1192.168.2.40x25No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 28, 2024 07:27:09.552586079 CEST1.1.1.1192.168.2.40xeb41No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:27:09.552586079 CEST1.1.1.1192.168.2.40xeb41No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 28, 2024 07:27:30.083276987 CEST1.1.1.1192.168.2.40x14a7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 28, 2024 07:27:30.083276987 CEST1.1.1.1192.168.2.40x14a7No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • dev-432403949340149124012.pantheonsite.io
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973523.185.0.24433320C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-28 05:26:19 UTC684OUTGET / HTTP/1.1
              Host: dev-432403949340149124012.pantheonsite.io
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-28 05:26:19 UTC560INHTTP/1.1 504 Target in maintenance
              Connection: close
              Content-Length: 616
              Retry-After: 0
              X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
              Content-Type: text/html; charset=utf-8
              Fastly-Restarts: 1
              Date: Sat, 28 Sep 2024 05:26:19 GMT
              Server: Pantheon
              X-Served-By: cache-chi-klot8100164-CHI, cache-nyc-kteb1890033-NYC
              X-Cache: MISS, MISS
              X-Cache-Hits: 0, 0
              X-Timer: S1727501180.594052,VS0,VE22
              Vary: Cookie, Cookie
              X-Robots-Tag: noindex
              Age: 0
              Accept-Ranges: bytes
              Via: 1.1 varnish, 1.1 varnish
              2024-09-28 05:26:19 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
              Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973623.185.0.24433320C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-28 05:26:19 UTC638OUTGET /favicon.ico HTTP/1.1
              Host: dev-432403949340149124012.pantheonsite.io
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://dev-432403949340149124012.pantheonsite.io/
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-28 05:26:19 UTC560INHTTP/1.1 504 Target in maintenance
              Connection: close
              Content-Length: 616
              Retry-After: 0
              X-pantheon-serious-reason: The web site you were looking for is currently undergoing maintenance.
              Content-Type: text/html; charset=utf-8
              Fastly-Restarts: 1
              Date: Sat, 28 Sep 2024 05:26:19 GMT
              Server: Pantheon
              X-Served-By: cache-chi-klot8100045-CHI, cache-ewr-kewr1740067-EWR
              X-Cache: MISS, MISS
              X-Cache-Hits: 0, 0
              X-Timer: S1727501180.776675,VS0,VE45
              Vary: Cookie, Cookie
              X-Robots-Tag: noindex
              Age: 0
              Accept-Ranges: bytes
              Via: 1.1 varnish, 1.1 varnish
              2024-09-28 05:26:19 UTC616INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 3e 0a 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 34 20 2d 20 54 61 72 67 65 74 20 69 6e 20 6d 61 69 6e 74 65 6e 61 6e 63 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 22 3e 0a 20 20 20 20 20 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 27 70 61 64 64 69 6e 67 2d 62 6c 6f 63 6b 3a 20 31 38 30 70 78 27 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
              Data Ascii: <!DOCTYPE HTML> <html> <head> <title>504 - Target in maintenance</title> </head> <body style="font-family:Arial, Helvetica, sans-serif; text-align: center"> <div style='padding-block: 180px'> <


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.4497402.18.97.153443
              TimestampBytes transferredDirectionData
              2024-09-28 05:26:23 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-28 05:26:23 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF67)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-neu-z1
              Cache-Control: public, max-age=213547
              Date: Sat, 28 Sep 2024 05:26:23 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.4497412.18.97.153443
              TimestampBytes transferredDirectionData
              2024-09-28 05:26:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-28 05:26:24 UTC535INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
              Cache-Control: public, max-age=213598
              Date: Sat, 28 Sep 2024 05:26:24 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-28 05:26:24 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:01:26:13
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:01:26:16
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2400,i,15705503142056863312,16820904315009918179,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:01:26:18
              Start date:28/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://dev-432403949340149124012.pantheonsite.io/"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly