Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://boaolecheng.com

Overview

General Information

Sample URL:http://boaolecheng.com
Analysis ID:1522622
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3568 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1792 --field-trial-handle=2032,i,15896338464557643688,13678355115372625821,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://boaolecheng.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://boaolecheng.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: boaolecheng.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: boaolecheng.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://boaolecheng.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: boaolecheng.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Mon, 30 Sep 2024 11:04:59 GMTContent-Type: text/htmlContent-Length: 548Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1792 --field-trial-handle=2032,i,15896338464557643688,13678355115372625821,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://boaolecheng.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1792 --field-trial-handle=2032,i,15896338464557643688,13678355115372625821,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://boaolecheng.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
boaolecheng.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
bg.microsoft.map.fastly.net0%VirustotalBrowse
www.google.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
www.google.com
142.250.186.100
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
boaolecheng.com
120.24.52.209
truefalseunknown
NameMaliciousAntivirus DetectionReputation
http://boaolecheng.com/false
    unknown
    http://boaolecheng.com/favicon.icofalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.186.100
      www.google.comUnited States
      15169GOOGLEUSfalse
      120.24.52.209
      boaolecheng.comChina
      37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
      142.250.74.196
      unknownUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1522622
      Start date and time:2024-09-30 13:03:58 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 1s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://boaolecheng.com
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@16/4@6/5
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.217.18.3, 172.217.18.110, 64.233.167.84, 34.104.35.123, 13.85.23.86, 199.232.210.172, 13.85.23.206, 192.229.221.95, 20.3.187.198, 142.250.186.67
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtSetInformationFile calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text, with CRLF line terminators
      Category:downloaded
      Size (bytes):548
      Entropy (8bit):4.688532577858027
      Encrypted:false
      SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
      MD5:370E16C3B7DBA286CFF055F93B9A94D8
      SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
      SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
      SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
      Malicious:false
      Reputation:low
      URL:http://boaolecheng.com/favicon.ico
      Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:gzip compressed data, from Unix, original size modulo 2^32 1326
      Category:downloaded
      Size (bytes):785
      Entropy (8bit):7.6767144640242275
      Encrypted:false
      SSDEEP:24:XwrHGj6Tg5uVz+NFWCToBvdvRJmDbLFbUaiQtO1l:XQHGj6kTULJmZ4xQEl
      MD5:2B92C4ED032A5AF2D07E52394696D55E
      SHA1:6349B9E1C938FFEE9F1A97052564E802FC7D46A8
      SHA-256:BAC1D275501ACF0E9C1B6DF424297BEE67224B168C3722698D046B1C693AD4AA
      SHA-512:CC4091121BD4618765B3DE5BF15033D6816C284B8F18BF4E8FF6B6B21B52EEE9E206FE2B4E4BD008B8D18A65D88E2B71A687763513CE6278B4BD1279EEDC8935
      Malicious:false
      Reputation:low
      URL:http://boaolecheng.com/
      Preview:..........uTKS.P.^...t....(....n:.u.H......J.g.V.Z.......L......?.M.....j'.$'....sn.)V..l..q...Nzx....%8.h.Ig88..g..P.".V..ju]]............,F8...L:&$)2.bXVH..ST..4.......fs.........B.|. f)..7z.k..,......8.$I........A).1.|..D....\....G2...-..<.[.....1Q..bqH...*.I.3..+....A>.....J....<.1...gB.&..F.4.)oj..L&.....3..1..a..........5>...7..$-C..$.!`7...2K.C.#.i....C...q`...4....8....|>.........o..tE..B.D..,'mL>.t...DE&..u.......#u=.l8.>....SCf.....V.../..yTm.."j....Q..j./3j_....[[=...D.>...F.m........A.2.I. ay.-...E...j...jh....~.u..\.g.3O..M.Qv...)......Q...RM.]...-5...8.Sv...*\....Z;R..h..].k..G..t...GZ]..C.f.l........uE.5s.=.t..:.i.m6,5...|..X.....j.f........Y..S.V..C.I.......,..*......H.ie..%.c.5..m...D...4a.}..kK.....l.......
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Sep 30, 2024 13:04:44.596995115 CEST49675443192.168.2.4173.222.162.32
      Sep 30, 2024 13:04:54.206681013 CEST49675443192.168.2.4173.222.162.32
      Sep 30, 2024 13:04:57.305442095 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:57.305939913 CEST4973780192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:57.310385942 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:57.310467958 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:57.310628891 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:57.310705900 CEST8049737120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:57.310781956 CEST4973780192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:57.315373898 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:58.442709923 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:58.496311903 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:59.317706108 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:04:59.317750931 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:04:59.318192959 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:04:59.318855047 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:04:59.318871975 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:04:59.319962025 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:59.324737072 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:59.770558119 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:04:59.814337015 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:04:59.999061108 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:04:59.999636889 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:04:59.999671936 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:00.000761032 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:00.000828981 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:00.003911972 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:00.003995895 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:00.048605919 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:00.048619032 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:00.095494986 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:00.376597881 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:00.376621008 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:00.376692057 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:00.379973888 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:00.379995108 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.024976015 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.025161028 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.030127048 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.030141115 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.030416965 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.079889059 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.543311119 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.583436012 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.728697062 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.729016066 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.729048967 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.729074955 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.729108095 CEST49740443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.729115009 CEST44349740184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.789017916 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.789110899 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:01.789248943 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.789755106 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:01.789791107 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.436763048 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.436860085 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:02.440458059 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:02.440490961 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.440903902 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.444763899 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:02.491401911 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.661287069 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.661407948 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:02.661465883 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:02.662580967 CEST49741443192.168.2.4184.28.90.27
      Sep 30, 2024 13:05:02.662621021 CEST44349741184.28.90.27192.168.2.4
      Sep 30, 2024 13:05:09.865904093 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:09.865964890 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:09.866250992 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:10.767793894 CEST4972380192.168.2.4199.232.214.172
      Sep 30, 2024 13:05:10.772990942 CEST8049723199.232.214.172192.168.2.4
      Sep 30, 2024 13:05:10.773051023 CEST4972380192.168.2.4199.232.214.172
      Sep 30, 2024 13:05:11.135696888 CEST49739443192.168.2.4142.250.186.100
      Sep 30, 2024 13:05:11.135740995 CEST44349739142.250.186.100192.168.2.4
      Sep 30, 2024 13:05:42.315448046 CEST4973780192.168.2.4120.24.52.209
      Sep 30, 2024 13:05:42.321588039 CEST8049737120.24.52.209192.168.2.4
      Sep 30, 2024 13:05:44.784149885 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:05:44.788994074 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:05:58.442883015 CEST8049737120.24.52.209192.168.2.4
      Sep 30, 2024 13:05:58.442945004 CEST4973780192.168.2.4120.24.52.209
      Sep 30, 2024 13:05:59.509902000 CEST4973780192.168.2.4120.24.52.209
      Sep 30, 2024 13:05:59.515075922 CEST8049737120.24.52.209192.168.2.4
      Sep 30, 2024 13:05:59.520443916 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:05:59.520467043 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:05:59.520576954 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:05:59.521068096 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:05:59.521079063 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:05:59.766783953 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:05:59.766853094 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:05:59.893573046 CEST4972480192.168.2.4199.232.214.172
      Sep 30, 2024 13:05:59.901906013 CEST8049724199.232.214.172192.168.2.4
      Sep 30, 2024 13:05:59.901966095 CEST4972480192.168.2.4199.232.214.172
      Sep 30, 2024 13:06:00.156092882 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:00.156789064 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:06:00.156821012 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:00.157963991 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:00.159434080 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:06:00.159624100 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:00.205914021 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:06:01.129787922 CEST4973680192.168.2.4120.24.52.209
      Sep 30, 2024 13:06:01.135701895 CEST8049736120.24.52.209192.168.2.4
      Sep 30, 2024 13:06:10.139874935 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:10.140052080 CEST44349750142.250.74.196192.168.2.4
      Sep 30, 2024 13:06:10.140120029 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:06:11.121964931 CEST49750443192.168.2.4142.250.74.196
      Sep 30, 2024 13:06:11.122000933 CEST44349750142.250.74.196192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Sep 30, 2024 13:04:54.891881943 CEST53590081.1.1.1192.168.2.4
      Sep 30, 2024 13:04:54.908252001 CEST53583121.1.1.1192.168.2.4
      Sep 30, 2024 13:04:55.884207964 CEST53514221.1.1.1192.168.2.4
      Sep 30, 2024 13:04:56.805557013 CEST5562053192.168.2.41.1.1.1
      Sep 30, 2024 13:04:56.805752993 CEST5149553192.168.2.41.1.1.1
      Sep 30, 2024 13:04:57.252265930 CEST53556201.1.1.1192.168.2.4
      Sep 30, 2024 13:04:57.304605007 CEST53514951.1.1.1192.168.2.4
      Sep 30, 2024 13:04:59.291321039 CEST5759653192.168.2.41.1.1.1
      Sep 30, 2024 13:04:59.296866894 CEST5012653192.168.2.41.1.1.1
      Sep 30, 2024 13:04:59.298448086 CEST53575961.1.1.1192.168.2.4
      Sep 30, 2024 13:04:59.303913116 CEST53501261.1.1.1192.168.2.4
      Sep 30, 2024 13:05:11.555208921 CEST138138192.168.2.4192.168.2.255
      Sep 30, 2024 13:05:13.106318951 CEST53535581.1.1.1192.168.2.4
      Sep 30, 2024 13:05:32.962758064 CEST53597081.1.1.1192.168.2.4
      Sep 30, 2024 13:05:54.357667923 CEST53585651.1.1.1192.168.2.4
      Sep 30, 2024 13:05:55.946991920 CEST53565141.1.1.1192.168.2.4
      Sep 30, 2024 13:05:59.511225939 CEST6290653192.168.2.41.1.1.1
      Sep 30, 2024 13:05:59.511411905 CEST5890153192.168.2.41.1.1.1
      Sep 30, 2024 13:05:59.518024921 CEST53629061.1.1.1192.168.2.4
      Sep 30, 2024 13:05:59.519186974 CEST53589011.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Sep 30, 2024 13:04:56.805557013 CEST192.168.2.41.1.1.10xd861Standard query (0)boaolecheng.comA (IP address)IN (0x0001)false
      Sep 30, 2024 13:04:56.805752993 CEST192.168.2.41.1.1.10x8c7cStandard query (0)boaolecheng.com65IN (0x0001)false
      Sep 30, 2024 13:04:59.291321039 CEST192.168.2.41.1.1.10xe34aStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Sep 30, 2024 13:04:59.296866894 CEST192.168.2.41.1.1.10xe7ccStandard query (0)www.google.com65IN (0x0001)false
      Sep 30, 2024 13:05:59.511225939 CEST192.168.2.41.1.1.10xc9beStandard query (0)www.google.comA (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:59.511411905 CEST192.168.2.41.1.1.10xe2f2Standard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Sep 30, 2024 13:04:57.252265930 CEST1.1.1.1192.168.2.40xd861No error (0)boaolecheng.com120.24.52.209A (IP address)IN (0x0001)false
      Sep 30, 2024 13:04:59.298448086 CEST1.1.1.1192.168.2.40xe34aNo error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
      Sep 30, 2024 13:04:59.303913116 CEST1.1.1.1192.168.2.40xe7ccNo error (0)www.google.com65IN (0x0001)false
      Sep 30, 2024 13:05:08.102404118 CEST1.1.1.1192.168.2.40x33bfNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:08.102404118 CEST1.1.1.1192.168.2.40x33bfNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:09.710639000 CEST1.1.1.1192.168.2.40xde72No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 13:05:09.710639000 CEST1.1.1.1192.168.2.40xde72No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:28.197678089 CEST1.1.1.1192.168.2.40xf1ecNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 13:05:28.197678089 CEST1.1.1.1192.168.2.40xf1ecNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:48.057930946 CEST1.1.1.1192.168.2.40xfd0fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 13:05:48.057930946 CEST1.1.1.1192.168.2.40xfd0fNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:59.518024921 CEST1.1.1.1192.168.2.40xc9beNo error (0)www.google.com142.250.74.196A (IP address)IN (0x0001)false
      Sep 30, 2024 13:05:59.519186974 CEST1.1.1.1192.168.2.40xe2f2No error (0)www.google.com65IN (0x0001)false
      Sep 30, 2024 13:06:07.418006897 CEST1.1.1.1192.168.2.40x6c9fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
      Sep 30, 2024 13:06:07.418006897 CEST1.1.1.1192.168.2.40x6c9fNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
      • fs.microsoft.com
      • boaolecheng.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449736120.24.52.209804464C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Sep 30, 2024 13:04:57.310628891 CEST430OUTGET / HTTP/1.1
      Host: boaolecheng.com
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Sep 30, 2024 13:04:58.442709923 CEST1062INHTTP/1.1 200 OK
      Server: nginx
      Date: Mon, 30 Sep 2024 11:04:58 GMT
      Content-Type: text/html
      Last-Modified: Wed, 26 Apr 2017 08:03:47 GMT
      Transfer-Encoding: chunked
      Connection: keep-alive
      Vary: Accept-Encoding
      ETag: W/"59005463-52e"
      Content-Encoding: gzip
      Data Raw: 33 31 31 0d 0a 1f 8b 08 00 00 00 00 00 00 03 75 54 4b 53 da 50 14 5e c3 af b8 c2 74 d3 19 9a f0 28 d5 10 d9 b4 9b 6e 3a dd 75 1d 48 02 99 06 c2 c0 b5 4a 19 67 94 56 d4 5a aa 8e e8 08 d2 a1 14 1f 4c 1d 82 d5 99 fa 80 d4 3f c3 4d c2 8a bf d0 9b 07 08 6a 27 8b 24 27 df f9 be f3 9d 73 6e e8 29 56 8a c2 6c 8a 03 71 98 10 c3 4e 7a 78 e3 18 16 bf 25 38 c8 80 68 9c 49 67 38 38 eb 9a 83 bc 67 da 85 c3 50 80 22 17 56 cf eb 6a 75 5d 5d ff 8b d6 ce b4 d3 b2 96 bf a6 09 eb 8b 93 ce c0 2c 46 38 9f e6 12 4c 3a 26 24 29 32 94 62 58 56 48 c6 f0 53 54 12 a5 34 e5 0e 04 02 8b ce 88 c4 66 73 bc 94 84 9e 8c f0 91 a3 bc 81 d4 42 c8 7c e5 99 84 20 66 29 17 92 37 7a ca 8e 6b d1 f9 2c c1 08 c9 dc bc c0 c2 38 15 24 49 8c b3 a9 bd e4 13 c0 cc 41 29 84 31 a6 7c 2e c2 44 df c7 d2 d2 5c 92 a5 80 db 47 32 cf fd 8c 2d 0a dc 3c cf 5b 02 a6 1e f0 06 31 51 9c 13 62 71 48 81 80 c1 2a 0a 49 ce 33 11 b1 2b f7 88 1c 8f 41 3e 03 84 a5 a2 b8 4a 2e 09 c7 c4 3c b6 31 de cf bf e0 67 42 c0 26 f1 9b c5 46 a4 34 cb a5 29 6f 6a 01 b0 4c 26 ce b1 [TRUNCATED]
      Data Ascii: 311uTKSP^t(n:uHJgVZL?Mj'$'sn)VlqNzx%8hIg88gP"Vju]],F8L:&$)2bXVHST4fsB| f)7zk,8$IA)1|.D\G2-<[1QbqH*I3+A>J.<1gB&F4)ojL&31a5>7$-C$!`72KC#iCq`48|>otEBD,'mL>tDE&u#u=l8>SCfV/yTm"jQj/3j_[[=.D>FmA2I ay-Ejjh~u\g3OMQv)QRM]-58Sv*\Z;Rh]kGtGZ]CfluE5s=t:im6,5|XjfYSVCI,*Hie%c5mD4a}kKl.0
      Sep 30, 2024 13:04:59.319962025 CEST374OUTGET /favicon.ico HTTP/1.1
      Host: boaolecheng.com
      Connection: keep-alive
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Referer: http://boaolecheng.com/
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9
      Sep 30, 2024 13:04:59.770558119 CEST696INHTTP/1.1 404 Not Found
      Server: nginx
      Date: Mon, 30 Sep 2024 11:04:59 GMT
      Content-Type: text/html
      Content-Length: 548
      Connection: keep-alive
      Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 [TRUNCATED]
      Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
      Sep 30, 2024 13:05:44.784149885 CEST6OUTData Raw: 00
      Data Ascii:


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449737120.24.52.209804464C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Sep 30, 2024 13:05:42.315448046 CEST6OUTData Raw: 00
      Data Ascii:


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449740184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-30 11:05:01 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-30 11:05:01 UTC466INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=25989
      Date: Mon, 30 Sep 2024 11:05:01 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449741184.28.90.27443
      TimestampBytes transferredDirectionData
      2024-09-30 11:05:02 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-09-30 11:05:02 UTC514INHTTP/1.1 200 OK
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (lpl/EF06)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-weu-z1
      Cache-Control: public, max-age=26050
      Date: Mon, 30 Sep 2024 11:05:02 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-09-30 11:05:02 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:07:04:48
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:07:04:53
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1792 --field-trial-handle=2032,i,15896338464557643688,13678355115372625821,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:07:04:56
      Start date:30/09/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://boaolecheng.com"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly