Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://thriveai.net/

Overview

General Information

Sample URL:https://thriveai.net/
Analysis ID:1522281
Tags:urlscan
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 736 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2296,i,18363694557623128021,11338976415862117992,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6344 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://thriveai.net/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.godaddy.com/forsale/thriveai.net?utm_source=TDFS_BINNS2&utm_medium=parkedpages&utm_campaign=x_corp_tdfs-binns2_base&traffic_type=TDFS_BINNS2&traffic_id=binns2&HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: thriveai.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /lander HTTP/1.1Host: thriveai.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://thriveai.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: thriveai.net
Source: global trafficDNS traffic detected: DNS query: www.godaddy.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49747 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2296,i,18363694557623128021,11338976415862117992,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://thriveai.net/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2296,i,18363694557623128021,11338976415862117992,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
thriveai.net
13.248.169.48
truefalse
    unknown
    www.google.com
    216.58.206.36
    truefalse
      unknown
      default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
      217.20.57.18
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          www.godaddy.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://www.godaddy.com/forsale/thriveai.net?utm_source=TDFS_BINNS2&utm_medium=parkedpages&utm_campaign=x_corp_tdfs-binns2_base&traffic_type=TDFS_BINNS2&traffic_id=binns2&false
              unknown
              https://thriveai.net/false
                unknown
                https://thriveai.net/landerfalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  13.248.169.48
                  thriveai.netUnited States
                  16509AMAZON-02USfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.206.36
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  192.168.2.5
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1522281
                  Start date and time:2024-09-29 15:54:55 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 10s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://thriveai.net/
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@17/4@6/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.185.195, 142.250.186.78, 142.251.173.84, 34.104.35.123, 23.201.246.20, 4.245.163.56, 217.20.57.18, 20.3.187.198, 192.229.221.95, 13.85.23.206, 216.58.206.35
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, e6001.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, wildcard-ipv6.godaddy.com.edgekey.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: https://thriveai.net/
                  No simulations
                  InputOutput
                  URL: https://www.godaddy.com/forsale/thriveai.net?utm_source=TDFS_BINNS2&utm_medium=parkedpages&utm_campaign=x_corp_tdfs-binns2_base&traffic_type=TDFS_BINNS2&traffic_id=binns2& Model: jbxai
                  {
                  "brand":[],
                  "contains_trigger_text":false,
                  "trigger_text":"",
                  "prominent_button_name":"unknown",
                  "text_input_field_labels":"unknown",
                  "pdf_icon_visible":false,
                  "has_visible_captcha":false,
                  "has_urgent_text":false,
                  "has_visible_qrcode":false}
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text
                  Category:downloaded
                  Size (bytes):384
                  Entropy (8bit):5.287918697259726
                  Encrypted:false
                  SSDEEP:6:wBqWekiTakpxxdGztoIhS3EaXqnRCsDPLCmKvFZrWbcaS3jfU0cMTFZrPT:dkK9dg5qEaXSc9/jfHJ
                  MD5:E7C8A4978AC410C239B5E2881F96A359
                  SHA1:A573B7BDF33BFD06F721134A0DCB910C403BA0ED
                  SHA-256:A4C1DE1134DB612429411C2FBC40208542BCB87B333079F64F32EE15AAB69420
                  SHA-512:F991D5EF008EE333671C8666C98C261B86B4B5CCCC94E76E053CED1EA64ED6AA56A9D8AB22584EC46111394B22577837D182DFEAEC089E58C5F5F408F9115330
                  Malicious:false
                  Reputation:low
                  URL:https://www.godaddy.com/favicon.ico
                  Preview:<HTML><HEAD>.<TITLE>Access Denied</TITLE>.</HEAD><BODY>.<H1>Access Denied</H1>. .You don't have permission to access "http&#58;&#47;&#47;www&#46;godaddy&#46;com&#47;favicon&#46;ico" on this server.<P>.Reference&#32;&#35;18&#46;9cf01002&#46;1727618155&#46;1768ef66.<P>https&#58;&#47;&#47;errors&#46;edgesuite&#46;net&#47;18&#46;9cf01002&#46;1727618155&#46;1768ef66</P>.</BODY>.</HTML>.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with no line terminators
                  Category:downloaded
                  Size (bytes):114
                  Entropy (8bit):4.802925647778009
                  Encrypted:false
                  SSDEEP:3:PouVIZx/XMn30EEBuvFfD0OkADYyT0NV9kBbZWM:hax/XW3/p5mmYyT0NVuB9d
                  MD5:E89F75F918DBDCEE28604D4E09DD71D7
                  SHA1:F9D9055E9878723A12063B47D4A1A5F58C3EB1E9
                  SHA-256:6DC9C7FC93BB488BB0520A6C780A8D3C0FB5486A4711ACA49B4C53FAC7393023
                  SHA-512:8DF0AB2E3679B64A6174DEFF4259AE5680F88E3AE307E0EA2DFFF88EC4BA14F3477C9FE3A5AA5DA3A8E857601170A5108ED75F6D6975958AC7A314E4A336AED0
                  Malicious:false
                  Reputation:low
                  URL:https://thriveai.net/
                  Preview:<!DOCTYPE html><html><head><script>window.onload=function(){window.location.href="/lander"}</script></head></html>
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 29, 2024 15:55:50.397241116 CEST49675443192.168.2.4173.222.162.32
                  Sep 29, 2024 15:55:52.816314936 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816343069 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:52.816498041 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816607952 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816657066 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:52.816770077 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816783905 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:52.816797972 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816972971 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:52.816987991 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.293626070 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.300618887 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.312817097 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.312861919 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.312930107 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.312954903 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.313882113 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.313945055 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.314656973 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.314718962 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.314888954 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.314954996 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.315236092 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.315326929 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.315412045 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.315419912 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.357475996 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.357477903 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.357491016 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.405472040 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.455869913 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.455951929 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.456031084 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.471102953 CEST49736443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.471120119 CEST4434973613.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.514519930 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.514561892 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.514662981 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.514976025 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.514986038 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.516889095 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.559403896 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.634706974 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.634815931 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.634913921 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.637193918 CEST49735443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.637211084 CEST4434973513.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.992258072 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.995575905 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.995589972 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.995976925 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:53.997416019 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:53.997479916 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:55:54.051644087 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:55:55.380023003 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:55.380049944 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:55.380147934 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:55.385457993 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:55.385467052 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.023583889 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.025764942 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:56.025782108 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.026818991 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.027005911 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:56.031043053 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:56.031136036 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.083611965 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:56.083626986 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:55:56.130633116 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:55:56.493786097 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:56.493837118 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:56.493904114 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:56.495853901 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:56.495878935 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.144536018 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.144666910 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.151091099 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.151099920 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.151370049 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.193007946 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.365637064 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.411395073 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.554837942 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.554917097 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.555006981 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.555267096 CEST49746443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.555284977 CEST44349746184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.591051102 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.591087103 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:57.591216087 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.591671944 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:57.591682911 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.236526012 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.236604929 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:58.238091946 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:58.238102913 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.238359928 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.239685059 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:58.287400961 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.514467001 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.514560938 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:55:58.514836073 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:58.518673897 CEST49747443192.168.2.4184.28.90.27
                  Sep 29, 2024 15:55:58.518721104 CEST44349747184.28.90.27192.168.2.4
                  Sep 29, 2024 15:56:05.937242985 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:05.937319040 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:05.937371969 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:07.786422014 CEST49743443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:07.786463022 CEST44349743216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:08.102145910 CEST4972380192.168.2.4199.232.210.172
                  Sep 29, 2024 15:56:08.107896090 CEST8049723199.232.210.172192.168.2.4
                  Sep 29, 2024 15:56:08.108031034 CEST4972380192.168.2.4199.232.210.172
                  Sep 29, 2024 15:56:39.006405115 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:56:39.006433964 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:56:55.413187027 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:56:55.413218021 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:55.413247108 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:55.413270950 CEST4434973713.248.169.48192.168.2.4
                  Sep 29, 2024 15:56:55.413336039 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:55.413336992 CEST49737443192.168.2.413.248.169.48
                  Sep 29, 2024 15:56:55.414138079 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:55.414153099 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:56.040659904 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:56.041059017 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:56.041079998 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:56.041410923 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:56.041923046 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:56.041989088 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:56:56.083796024 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:56:56.990019083 CEST4972480192.168.2.4199.232.210.172
                  Sep 29, 2024 15:56:56.996640921 CEST8049724199.232.210.172192.168.2.4
                  Sep 29, 2024 15:56:56.996700048 CEST4972480192.168.2.4199.232.210.172
                  Sep 29, 2024 15:57:05.962553024 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:57:05.962626934 CEST44349756216.58.206.36192.168.2.4
                  Sep 29, 2024 15:57:05.962798119 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:57:07.742197037 CEST49756443192.168.2.4216.58.206.36
                  Sep 29, 2024 15:57:07.742222071 CEST44349756216.58.206.36192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Sep 29, 2024 15:55:51.589323044 CEST53537121.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:51.599679947 CEST53646561.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:52.580178976 CEST53564371.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:52.780795097 CEST5995453192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:52.780908108 CEST5227553192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:52.815262079 CEST53522751.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:52.815753937 CEST53599541.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:53.646482944 CEST5946253192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:53.646914959 CEST6494553192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:55.359731913 CEST6186653192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:55.362082005 CEST5927153192.168.2.41.1.1.1
                  Sep 29, 2024 15:55:55.366782904 CEST53618661.1.1.1192.168.2.4
                  Sep 29, 2024 15:55:55.369524002 CEST53592711.1.1.1192.168.2.4
                  Sep 29, 2024 15:56:08.544855118 CEST138138192.168.2.4192.168.2.255
                  Sep 29, 2024 15:56:09.918333054 CEST53620611.1.1.1192.168.2.4
                  Sep 29, 2024 15:56:28.718842030 CEST53601501.1.1.1192.168.2.4
                  Sep 29, 2024 15:56:51.124433994 CEST53579261.1.1.1192.168.2.4
                  Sep 29, 2024 15:56:51.597347021 CEST53581211.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Sep 29, 2024 15:55:52.780795097 CEST192.168.2.41.1.1.10x6facStandard query (0)thriveai.netA (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:52.780908108 CEST192.168.2.41.1.1.10x8b7Standard query (0)thriveai.net65IN (0x0001)false
                  Sep 29, 2024 15:55:53.646482944 CEST192.168.2.41.1.1.10x9777Standard query (0)www.godaddy.comA (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:53.646914959 CEST192.168.2.41.1.1.10x6716Standard query (0)www.godaddy.com65IN (0x0001)false
                  Sep 29, 2024 15:55:55.359731913 CEST192.168.2.41.1.1.10x9d0dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:55.362082005 CEST192.168.2.41.1.1.10xa385Standard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Sep 29, 2024 15:55:52.815753937 CEST1.1.1.1192.168.2.40x6facNo error (0)thriveai.net13.248.169.48A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:52.815753937 CEST1.1.1.1192.168.2.40x6facNo error (0)thriveai.net76.223.54.146A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:53.655227900 CEST1.1.1.1192.168.2.40x9777No error (0)www.godaddy.comwildcard-ipv6.godaddy.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:55:53.664830923 CEST1.1.1.1192.168.2.40x6716No error (0)www.godaddy.comwildcard-ipv6.godaddy.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:55:55.366782904 CEST1.1.1.1192.168.2.40x9d0dNo error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:55:55.369524002 CEST1.1.1.1192.168.2.40xa385No error (0)www.google.com65IN (0x0001)false
                  Sep 29, 2024 15:56:04.656404972 CEST1.1.1.1192.168.2.40x651dNo error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:56:04.656404972 CEST1.1.1.1192.168.2.40x651dNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.18A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:56:04.656404972 CEST1.1.1.1192.168.2.40x651dNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.34A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:56:06.827955008 CEST1.1.1.1192.168.2.40x756eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:56:06.827955008 CEST1.1.1.1192.168.2.40x756eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:56:24.999598980 CEST1.1.1.1192.168.2.40x96dbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:56:24.999598980 CEST1.1.1.1192.168.2.40x96dbNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:56:43.799823046 CEST1.1.1.1192.168.2.40xd7d2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:56:43.799823046 CEST1.1.1.1192.168.2.40xd7d2No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Sep 29, 2024 15:57:04.263850927 CEST1.1.1.1192.168.2.40x7ab8No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Sep 29, 2024 15:57:04.263850927 CEST1.1.1.1192.168.2.40x7ab8No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  • thriveai.net
                  • https:
                  • fs.microsoft.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44973613.248.169.48443736C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-09-29 13:55:53 UTC655OUTGET / HTTP/1.1
                  Host: thriveai.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-09-29 13:55:53 UTC121INHTTP/1.1 200 OK
                  Content-Type: text/html
                  Date: Sun, 29 Sep 2024 13:55:53 GMT
                  Content-Length: 114
                  Connection: close
                  2024-09-29 13:55:53 UTC114INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 73 63 72 69 70 74 3e 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3d 22 2f 6c 61 6e 64 65 72 22 7d 3c 2f 73 63 72 69 70 74 3e 3c 2f 68 65 61 64 3e 3c 2f 68 74 6d 6c 3e
                  Data Ascii: <!DOCTYPE html><html><head><script>window.onload=function(){window.location.href="/lander"}</script></head></html>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44973513.248.169.48443736C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-09-29 13:55:53 UTC680OUTGET /lander HTTP/1.1
                  Host: thriveai.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-Dest: document
                  Referer: https://thriveai.net/
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-09-29 13:55:53 UTC851INHTTP/1.1 307 Temporary Redirect
                  Content-Type: text/html; charset=utf-8
                  Location: https://www.godaddy.com/forsale/thriveai.net?utm_source=TDFS_BINNS2&utm_medium=parkedpages&utm_campaign=x_corp_tdfs-binns2_base&traffic_type=TDFS_BINNS2&traffic_id=binns2&
                  Set-Cookie: fb_sessiontraffic=S_TOUCH=&pathway=8b527435-1c60-4768-8f56-783b4bf1c3cc&V_DATE=&pc=0; Path=/; Domain=afternic.com; Expires=Sun, 29 Sep 2024 14:15:53 GMT
                  Set-Cookie: pathway=8b527435-1c60-4768-8f56-783b4bf1c3cc; Path=/; Domain=afternic.com; Expires=Sun, 29 Sep 2024 14:15:53 GMT
                  Set-Cookie: visitor=vid=8b527435-1c60-4768-8f56-783b4bf1c3cc; Path=/; Domain=afternic.com; Expires=Sun, 28 Sep 2025 13:55:53 GMT
                  Set-Cookie: market=en-US; Path=/; Domain=afternic.com; Expires=Mon, 29 Sep 2025 13:55:53 GMT
                  Date: Sun, 29 Sep 2024 13:55:53 GMT
                  Content-Length: 227
                  Connection: close
                  2024-09-29 13:55:53 UTC227INData Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 64 61 64 64 79 2e 63 6f 6d 2f 66 6f 72 73 61 6c 65 2f 74 68 72 69 76 65 61 69 2e 6e 65 74 3f 75 74 6d 5f 73 6f 75 72 63 65 3d 54 44 46 53 5f 42 49 4e 4e 53 32 26 61 6d 70 3b 75 74 6d 5f 6d 65 64 69 75 6d 3d 70 61 72 6b 65 64 70 61 67 65 73 26 61 6d 70 3b 75 74 6d 5f 63 61 6d 70 61 69 67 6e 3d 78 5f 63 6f 72 70 5f 74 64 66 73 2d 62 69 6e 6e 73 32 5f 62 61 73 65 26 61 6d 70 3b 74 72 61 66 66 69 63 5f 74 79 70 65 3d 54 44 46 53 5f 42 49 4e 4e 53 32 26 61 6d 70 3b 74 72 61 66 66 69 63 5f 69 64 3d 62 69 6e 6e 73 32 26 61 6d 70 3b 22 3e 54 65 6d 70 6f 72 61 72 79 20 52 65 64 69 72 65 63 74 3c 2f 61 3e 2e 0a 0a
                  Data Ascii: <a href="https://www.godaddy.com/forsale/thriveai.net?utm_source=TDFS_BINNS2&amp;utm_medium=parkedpages&amp;utm_campaign=x_corp_tdfs-binns2_base&amp;traffic_type=TDFS_BINNS2&amp;traffic_id=binns2&amp;">Temporary Redirect</a>.


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449746184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-09-29 13:55:57 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-09-29 13:55:57 UTC466INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF67)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-neu-z1
                  Cache-Control: public, max-age=96545
                  Date: Sun, 29 Sep 2024 13:55:57 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.449747184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-09-29 13:55:58 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-09-29 13:55:58 UTC514INHTTP/1.1 200 OK
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-weu-z1
                  Cache-Control: public, max-age=96574
                  Date: Sun, 29 Sep 2024 13:55:58 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-09-29 13:55:58 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:09:55:44
                  Start date:29/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:09:55:49
                  Start date:29/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2296,i,18363694557623128021,11338976415862117992,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:09:55:51
                  Start date:29/09/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://thriveai.net/"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly