Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1

Overview

General Information

Sample URL:https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-
Analysis ID:1522872
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 3812 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2028,i,12579888137249560955,8188856835202488069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4304 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49724 version: TLS 1.0
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.5:50264 -> 162.159.36.2:53
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49724 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1 HTTP/1.1Host: content.app-us1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: content.app-us1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: content.app-us1.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A410900D492X-BM-CBT: 1696428841X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 120X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A410900D492X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticshX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2484Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1727717233459&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 30 Sep 2024 17:27:30 GMTContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closex-envoy-upstream-service-time: 11CF-Cache-Status: DYNAMICStrict-Transport-Security: max-age=63072000; includeSubDomains; preloadServer: cloudflareCF-RAY: 8cb5ec8d398f728f-EWR
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 30 Sep 2024 17:27:30 GMTContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closex-envoy-upstream-service-time: 11CF-Cache-Status: MISSStrict-Transport-Security: max-age=63072000; includeSubDomains; preloadServer: cloudflareCF-RAY: 8cb5ec8f09c019bb-EWR
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50268
Source: unknownNetwork traffic detected: HTTP traffic on port 50268 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: classification engineClassification label: clean1.win@16/10@6/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2028,i,12579888137249560955,8188856835202488069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2028,i,12579888137249560955,8188856835202488069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    content.app-us1.com
    104.17.31.174
    truefalse
      unknown
      www.google.com
      216.58.212.164
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1false
            unknown
            https://content.app-us1.com/favicon.icofalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.186.36
              unknownUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              216.58.212.164
              www.google.comUnited States
              15169GOOGLEUSfalse
              104.17.31.174
              content.app-us1.comUnited States
              13335CLOUDFLARENETUSfalse
              IP
              192.168.2.13
              192.168.2.23
              192.168.2.5
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1522872
              Start date and time:2024-09-30 19:26:35 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 2s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean1.win@16/10@6/7
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.18.3, 66.102.1.84, 142.250.186.46, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.221.95, 13.95.31.18, 20.242.39.171, 52.165.164.15, 142.250.185.131, 93.184.221.240
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, d.4.1.9.1.6.7.1.0.0.0.0.0.0.0.0.1.0.0.9.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, update.googleapis.com, hlb.apr-52dd2-0.edgecastdns.net, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 16:27:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.9732859132629903
              Encrypted:false
              SSDEEP:48:8ed9Tl5YHVteidAKZdA19ehwiZUklqehsJy+3:8obGqBJy
              MD5:AEF3447208FAE1A16D792A386DC2137E
              SHA1:0C1F8DFC61271607FF9F78273EB48E6AC08AF05E
              SHA-256:7924BD1C0A6C765366E003D1E002F8DFFCE77AC41E46AB82F3089568CA1062C0
              SHA-512:A81897BA71A38DB3067C4452E7D7B4427A41933BBD1A6AB826E7C05F3BD1E10283D24235A356490597094F06D608BB7659E50E2B2DD4D219E777ED67DB001C57
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,........^...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Yo............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 16:27:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2679
              Entropy (8bit):3.9887801051984266
              Encrypted:false
              SSDEEP:48:8Xd9Tl5YHVteidAKZdA1weh/iZUkAQkqehxJy+2:8rbGg9Q+Jy
              MD5:9741036473AD4932B6338F920D95E3BE
              SHA1:E07D11911F307C378CCBC5EE066CCD1BCC97E0E4
              SHA-256:9A3980026C88A45118E23B108AA96554906C8549DFBC96B576B5164C947601C9
              SHA-512:28E6DF47546C8EC28CA6452F17E28F32A5D428BDC6287EEE98D434DE62CF2FECE3CA2F699D3DFDE0B9BE1EBB0FC7F4A23E3673C9535B24C26E9B8F99F7CBF658
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....M..^...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Yo............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2693
              Entropy (8bit):4.001010306412778
              Encrypted:false
              SSDEEP:48:8xid9Tl5sHVteidAKZdA14tseh7sFiZUkmgqeh7srJy+BX:8xcb64ndJy
              MD5:A7BD9B205BD225588F914133B1771A88
              SHA1:4515BA8186F2AB610C260CF0DEC3DC084DB8BBD0
              SHA-256:512E84EE75CD489BE514303AC2B7F55DC54EDB3976E7B166607A41D1E6F550A9
              SHA-512:8BF69F3D58B7D13F6D13211FE54B42CAEC03516B9C6C3C1916C68AC09A8DD73959CB3A8F67698B1AD8FF669D676CD7162EF2FAF98F321418FAB41441EB756612
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 16:27:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.9893809019890702
              Encrypted:false
              SSDEEP:48:8djd9Tl5YHVteidAKZdA1vehDiZUkwqeh1Jy+R:8d3bGrjJy
              MD5:8E2D3AD8CDECEA23B44B7FEB5E30437D
              SHA1:59D69CA9270138A7FE366FB215F9F97BAC8512B6
              SHA-256:CD50C998AE3FF5B87F5E4E9EF78D26EA72634E463A033303BB6943D3A202BFEA
              SHA-512:3C2A2679F2A69A69A0B118350A7E3E8BA44D222EAF7C8CD7E8687CB693641B77336FCE87A07D49083D7BCF80DDAA7D9BFE96849F5F4D31C59B793659A728AB71
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,........^...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Yo............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 16:27:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.976768759768124
              Encrypted:false
              SSDEEP:48:8fd9Tl5YHVteidAKZdA1hehBiZUk1W1qehnJy+C:8DbGr9HJy
              MD5:0B6755A09A87145B048AD903BE7FBC06
              SHA1:6D2ECE73E87667E359759C29B9619F82D399B438
              SHA-256:243FAD7D744788B450FA48901FE9ED8C4AF086E9FC62D6335E64F7EE6E2733A2
              SHA-512:42D3B71B48649E76D7483B5968518033109571F657DFAC144AE7FF2BB705F3E1A089571A78E46702C5D3DB446055D45D1B450E7A1AB6E10668AB6045DD35B902
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....9..^...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Yo............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 16:27:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2683
              Entropy (8bit):3.9850947640803174
              Encrypted:false
              SSDEEP:48:81d9Tl5YHVteidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbdJy+yT+:8VbGLT/TbxWOvTbdJy7T
              MD5:019908A9F621575A16AB78ECF882BF30
              SHA1:8CA982C54606F5B9B224FF7B5932E72617E3F986
              SHA-256:C36F33FCEE774A53CE0D02E72E257E24C7540F4DBE033BC6D5758E7B3A6742D4
              SHA-512:33415B273CECC21A4D15B7C7F5EA23497EEDB75A1A41C28E0C00C463B308FEC6EF87ADDBAC0A684BC7E5CA342D159D57C7AE553C252125732401D3CB5292843D
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....q...^...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I>Yn.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V>Yn.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V>Yn.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V>Yn............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V>Yo............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............sa......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text
              Category:downloaded
              Size (bytes):243
              Entropy (8bit):5.586169688264538
              Encrypted:false
              SSDEEP:6:TMVBd/ZbZjZvKtWRVzjstapP1QGTqZ5VunU5PKjan:TMHd9BZKtWRyQR1QTZPuOPKja
              MD5:AED39F23DE8915ADD416BABD2152E72F
              SHA1:F34D31B89BA8B6B3A44228CA7276B55D4F115A7B
              SHA-256:617002D2072916ED5880ACC2C752DD94D2741D76BE3950CA4C9182AED55557EE
              SHA-512:5AF01EC99D3A5331BC5D16B57BF060416F6AEF4C240A1E834A6834DFF6162BA43507AE8F3AC2304973A4C1A02D33A572327B7569A4246530870BA80900894E10
              Malicious:false
              Reputation:low
              URL:"https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1"
              Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>DZ0XWHNJNPRET454</RequestId><HostId>uUEm387l5iy+R95BavYu/Yl9Ht3zRHbs4kK0SMTMnIymT7EikeqbWs1MJmfdLyWA2rFKvrGz3q8=</HostId></Error>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text
              Category:downloaded
              Size (bytes):275
              Entropy (8bit):5.726034348031062
              Encrypted:false
              SSDEEP:6:TMVBd/ZbZjZvKtWRVzj4zl1A7TOBtJNya7Ud4SC89FYan:TMHd9BZKtWRmpSYJNBU7jYa
              MD5:9F75A6D7002980B98EB241806D8FC298
              SHA1:15DF836711B596251BCD4206B59053481BBD097A
              SHA-256:1969BB7892F1B7B9251045302F90DB8A593AFBE4B84458B00952F625793C638E
              SHA-512:6998BE2A6F99947AB0DEB73A924F96495CE74E48938C5774599BE0E9BBD83E471A176C0A955B1DA6DD8545B1713A6ADE28EDBB743439977E650BEE262724D909
              Malicious:false
              Reputation:low
              URL:https://content.app-us1.com/favicon.ico
              Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>DZ0YVWSKDKRF3946</RequestId><HostId>L9i0Pm02jItPsGNDnU6Sl05A/5kI0/et8xyGfQb+6TZdIxWCDO0nOBRSPz6F4X7YX39Xgyy8cv4o7QCvnm6pPxr545yaakvWshC70bYmbSg=</HostId></Error>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Sep 30, 2024 19:27:23.238285065 CEST49674443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:23.238286018 CEST49675443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:23.347640038 CEST49673443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:29.565005064 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565052986 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:29.565124989 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565418005 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565427065 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:29.565478086 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565779924 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565793991 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:29.565918922 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:29.565932035 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.038739920 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.039024115 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.039043903 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.040134907 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.040199041 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.041342020 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.041409016 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.041544914 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.041553974 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.053071976 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.053314924 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.053324938 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.054362059 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.054423094 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.054802895 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.054863930 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.090399027 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.105376005 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.105390072 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.146392107 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.223392963 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.223526955 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.223579884 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.229270935 CEST49710443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.229285955 CEST44349710104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.348362923 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.391412973 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.491852045 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.491975069 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:30.492024899 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.493390083 CEST49709443192.168.2.5104.17.31.174
              Sep 30, 2024 19:27:30.493407965 CEST44349709104.17.31.174192.168.2.5
              Sep 30, 2024 19:27:32.262568951 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.262608051 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:32.262718916 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.263310909 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.263324976 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:32.839632034 CEST49674443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:32.839633942 CEST49675443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:32.904723883 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:32.947933912 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.947952986 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:32.949024916 CEST49673443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:32.949194908 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:32.949270010 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.967248917 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:32.967349052 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:33.011507034 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:33.011524916 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:33.057531118 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:33.302277088 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:33.302316904 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:33.302458048 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:33.307549000 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:33.307574034 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:33.956588030 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:33.956687927 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:33.965089083 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:33.965100050 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:33.965415001 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.011501074 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.159693956 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.207396030 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.346816063 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.347117901 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.347134113 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.347162962 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.347193003 CEST49715443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.347244024 CEST44349715184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.420963049 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.420985937 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.421242952 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.422142029 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:34.422154903 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:34.658746958 CEST4434970323.1.237.91192.168.2.5
              Sep 30, 2024 19:27:34.658879995 CEST49703443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:35.088490963 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.088562965 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.090050936 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.090059042 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.090308905 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.091701031 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.135404110 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.556834936 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.604785919 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.604804993 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.605381966 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.605397940 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.605473995 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:35.605603933 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.605642080 CEST44349716184.28.90.27192.168.2.5
              Sep 30, 2024 19:27:35.605686903 CEST49716443192.168.2.5184.28.90.27
              Sep 30, 2024 19:27:42.809046984 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:42.809113979 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:42.812350035 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:44.362740993 CEST49714443192.168.2.5216.58.212.164
              Sep 30, 2024 19:27:44.362763882 CEST44349714216.58.212.164192.168.2.5
              Sep 30, 2024 19:27:45.419056892 CEST49703443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:45.419183016 CEST49703443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:45.419568062 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:45.419596910 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:45.419656038 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:45.420100927 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:45.420121908 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:45.423926115 CEST4434970323.1.237.91192.168.2.5
              Sep 30, 2024 19:27:45.423994064 CEST4434970323.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.019649982 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.019728899 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.065777063 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.065810919 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.066188097 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.066281080 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.069279909 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.069360018 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.072362900 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.072376966 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.358489037 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.358573914 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.358702898 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:27:46.358738899 CEST4434972423.1.237.91192.168.2.5
              Sep 30, 2024 19:27:46.358803034 CEST49724443192.168.2.523.1.237.91
              Sep 30, 2024 19:28:11.519139051 CEST5026453192.168.2.5162.159.36.2
              Sep 30, 2024 19:28:11.524005890 CEST5350264162.159.36.2192.168.2.5
              Sep 30, 2024 19:28:11.524072886 CEST5026453192.168.2.5162.159.36.2
              Sep 30, 2024 19:28:11.524112940 CEST5026453192.168.2.5162.159.36.2
              Sep 30, 2024 19:28:11.529330969 CEST5350264162.159.36.2192.168.2.5
              Sep 30, 2024 19:28:11.978868008 CEST5350264162.159.36.2192.168.2.5
              Sep 30, 2024 19:28:11.979455948 CEST5026453192.168.2.5162.159.36.2
              Sep 30, 2024 19:28:11.984910965 CEST5350264162.159.36.2192.168.2.5
              Sep 30, 2024 19:28:11.984978914 CEST5026453192.168.2.5162.159.36.2
              Sep 30, 2024 19:28:32.312704086 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:32.312722921 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:32.312804937 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:32.313555002 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:32.313569069 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:33.123604059 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:33.124628067 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:33.124648094 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:33.124964952 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:33.125713110 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:33.125773907 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:33.168133974 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:42.908206940 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:42.908277988 CEST44350268142.250.186.36192.168.2.5
              Sep 30, 2024 19:28:42.908345938 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:44.168304920 CEST50268443192.168.2.5142.250.186.36
              Sep 30, 2024 19:28:44.168339968 CEST44350268142.250.186.36192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              Sep 30, 2024 19:27:27.911490917 CEST53559821.1.1.1192.168.2.5
              Sep 30, 2024 19:27:28.019798994 CEST53591371.1.1.1192.168.2.5
              Sep 30, 2024 19:27:29.187532902 CEST53517291.1.1.1192.168.2.5
              Sep 30, 2024 19:27:29.546699047 CEST5328153192.168.2.51.1.1.1
              Sep 30, 2024 19:27:29.546845913 CEST5034553192.168.2.51.1.1.1
              Sep 30, 2024 19:27:29.554642916 CEST53503451.1.1.1192.168.2.5
              Sep 30, 2024 19:27:29.564143896 CEST53532811.1.1.1192.168.2.5
              Sep 30, 2024 19:27:32.251979113 CEST5756453192.168.2.51.1.1.1
              Sep 30, 2024 19:27:32.252157927 CEST5884553192.168.2.51.1.1.1
              Sep 30, 2024 19:27:32.260663033 CEST53588451.1.1.1192.168.2.5
              Sep 30, 2024 19:27:32.260890007 CEST53575641.1.1.1192.168.2.5
              Sep 30, 2024 19:27:46.175497055 CEST53634591.1.1.1192.168.2.5
              Sep 30, 2024 19:28:05.098402977 CEST53544471.1.1.1192.168.2.5
              Sep 30, 2024 19:28:11.518450975 CEST5352284162.159.36.2192.168.2.5
              Sep 30, 2024 19:28:12.010459900 CEST53601761.1.1.1192.168.2.5
              Sep 30, 2024 19:28:27.438210964 CEST53492401.1.1.1192.168.2.5
              Sep 30, 2024 19:28:27.726053953 CEST53583681.1.1.1192.168.2.5
              Sep 30, 2024 19:28:32.302524090 CEST6332153192.168.2.51.1.1.1
              Sep 30, 2024 19:28:32.302742958 CEST5840153192.168.2.51.1.1.1
              Sep 30, 2024 19:28:32.309900045 CEST53633211.1.1.1192.168.2.5
              Sep 30, 2024 19:28:32.310045958 CEST53584011.1.1.1192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 30, 2024 19:27:29.546699047 CEST192.168.2.51.1.1.10x6450Standard query (0)content.app-us1.comA (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:29.546845913 CEST192.168.2.51.1.1.10xb8a9Standard query (0)content.app-us1.com65IN (0x0001)false
              Sep 30, 2024 19:27:32.251979113 CEST192.168.2.51.1.1.10x93e0Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:32.252157927 CEST192.168.2.51.1.1.10xd8a6Standard query (0)www.google.com65IN (0x0001)false
              Sep 30, 2024 19:28:32.302524090 CEST192.168.2.51.1.1.10x5544Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 30, 2024 19:28:32.302742958 CEST192.168.2.51.1.1.10xbd8fStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 30, 2024 19:27:29.554642916 CEST1.1.1.1192.168.2.50xb8a9No error (0)content.app-us1.com65IN (0x0001)false
              Sep 30, 2024 19:27:29.564143896 CEST1.1.1.1192.168.2.50x6450No error (0)content.app-us1.com104.17.31.174A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:29.564143896 CEST1.1.1.1192.168.2.50x6450No error (0)content.app-us1.com104.18.128.216A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:32.260663033 CEST1.1.1.1192.168.2.50xd8a6No error (0)www.google.com65IN (0x0001)false
              Sep 30, 2024 19:27:32.260890007 CEST1.1.1.1192.168.2.50x93e0No error (0)www.google.com216.58.212.164A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:43.061820030 CEST1.1.1.1192.168.2.50x2f90No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:43.061820030 CEST1.1.1.1192.168.2.50x2f90No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:43.915333986 CEST1.1.1.1192.168.2.50x7859No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 19:27:43.915333986 CEST1.1.1.1192.168.2.50x7859No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 19:27:57.426645041 CEST1.1.1.1192.168.2.50x3a50No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 19:27:57.426645041 CEST1.1.1.1192.168.2.50x3a50No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 19:28:20.208830118 CEST1.1.1.1192.168.2.50xb194No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 19:28:20.208830118 CEST1.1.1.1192.168.2.50xb194No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 19:28:32.309900045 CEST1.1.1.1192.168.2.50x5544No error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
              Sep 30, 2024 19:28:32.310045958 CEST1.1.1.1192.168.2.50xbd8fNo error (0)www.google.com65IN (0x0001)false
              Sep 30, 2024 19:28:40.519833088 CEST1.1.1.1192.168.2.50xe83eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 19:28:40.519833088 CEST1.1.1.1192.168.2.50xe83eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • content.app-us1.com
              • https:
                • www.bing.com
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.549710104.17.31.1744436276C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-30 17:27:30 UTC842OUTGET /0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1 HTTP/1.1
              Host: content.app-us1.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-30 17:27:30 UTC325INHTTP/1.1 403 Forbidden
              Date: Mon, 30 Sep 2024 17:27:30 GMT
              Content-Type: application/xml
              Transfer-Encoding: chunked
              Connection: close
              x-envoy-upstream-service-time: 11
              CF-Cache-Status: DYNAMIC
              Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
              Server: cloudflare
              CF-RAY: 8cb5ec8d398f728f-EWR
              2024-09-30 17:27:30 UTC249INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 44 5a 30 58 57 48 4e 4a 4e 50 52 45 54 34 35 34 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 75 55 45 6d 33 38 37 6c 35 69 79 2b 52 39 35 42 61 76 59 75 2f 59 6c 39 48 74 33 7a 52 48 62 73 34 6b 4b 30 53 4d 54 4d 6e 49 79 6d 54 37 45 69 6b 65 71 62 57 73 31 4d 4a 6d 66 64 4c 79 57 41 32 72 46 4b 76 72 47 7a 33 71 38 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a
              Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>DZ0XWHNJNPRET454</RequestId><HostId>uUEm387l5iy+R95BavYu/Yl9Ht3zRHbs4kK0SMTMnIymT7EikeqbWs1MJmfdLyWA2rFKvrGz3q8=</HostId></Error>
              2024-09-30 17:27:30 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.549709104.17.31.1744436276C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-30 17:27:30 UTC774OUTGET /favicon.ico HTTP/1.1
              Host: content.app-us1.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-30 17:27:30 UTC322INHTTP/1.1 403 Forbidden
              Date: Mon, 30 Sep 2024 17:27:30 GMT
              Content-Type: application/xml
              Transfer-Encoding: chunked
              Connection: close
              x-envoy-upstream-service-time: 11
              CF-Cache-Status: MISS
              Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
              Server: cloudflare
              CF-RAY: 8cb5ec8f09c019bb-EWR
              2024-09-30 17:27:30 UTC282INData Raw: 31 31 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 44 5a 30 59 56 57 53 4b 44 4b 52 46 33 39 34 36 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 4c 39 69 30 50 6d 30 32 6a 49 74 50 73 47 4e 44 6e 55 36 53 6c 30 35 41 2f 35 6b 49 30 2f 65 74 38 78 79 47 66 51 62 2b 36 54 5a 64 49 78 57 43 44 4f 30 6e 4f 42 52 53 50 7a 36 46 34 58 37 59 58 33 39 58 67 79 79 38 63 76 34 6f 37 51 43 76 6e 6d 36 70 50 78 72 35 34 35 79 61 61 6b 76 57 73 68 43 37
              Data Ascii: 113<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>DZ0YVWSKDKRF3946</RequestId><HostId>L9i0Pm02jItPsGNDnU6Sl05A/5kI0/et8xyGfQb+6TZdIxWCDO0nOBRSPz6F4X7YX39Xgyy8cv4o7QCvnm6pPxr545yaakvWshC7
              2024-09-30 17:27:30 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.549715184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-30 17:27:34 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-30 17:27:34 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-neu-z1
              Cache-Control: public, max-age=256696
              Date: Mon, 30 Sep 2024 17:27:34 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.549716184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-30 17:27:35 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-30 17:27:35 UTC515INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=256639
              Date: Mon, 30 Sep 2024 17:27:35 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-30 17:27:35 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Session IDSource IPSource PortDestination IPDestination Port
              4192.168.2.54972423.1.237.91443
              TimestampBytes transferredDirectionData
              2024-09-30 17:27:46 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
              Origin: https://www.bing.com
              Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
              Accept: */*
              Accept-Language: en-CH
              Content-type: text/xml
              X-Agent-DeviceId: 01000A410900D492
              X-BM-CBT: 1696428841
              X-BM-DateFormat: dd/MM/yyyy
              X-BM-DeviceDimensions: 784x984
              X-BM-DeviceDimensionsLogical: 784x984
              X-BM-DeviceScale: 100
              X-BM-DTZ: 120
              X-BM-Market: CH
              X-BM-Theme: 000000;0078d7
              X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
              X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
              X-Device-isOptin: false
              X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
              X-Device-OSSKU: 48
              X-Device-Touch: false
              X-DeviceID: 01000A410900D492
              X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
              X-MSEdge-ExternalExpType: JointCoord
              X-PositionerType: Desktop
              X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
              X-Search-CortanaAvailableCapabilities: None
              X-Search-SafeSearch: Moderate
              X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
              X-UserAgeClass: Unknown
              Accept-Encoding: gzip, deflate, br
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
              Host: www.bing.com
              Content-Length: 2484
              Connection: Keep-Alive
              Cache-Control: no-cache
              Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1727717233459&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
              2024-09-30 17:27:46 UTC1OUTData Raw: 3c
              Data Ascii: <
              2024-09-30 17:27:46 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
              Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
              2024-09-30 17:27:46 UTC480INHTTP/1.1 204 No Content
              Access-Control-Allow-Origin: *
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              X-MSEdge-Ref: Ref A: BE05D1ADC9044364868AF982B34379F6 Ref B: LAX311000113051 Ref C: 2024-09-30T17:27:46Z
              Date: Mon, 30 Sep 2024 17:27:46 GMT
              Connection: close
              Alt-Svc: h3=":443"; ma=93600
              X-CDN-TraceID: 0.15ed0117.1727717266.38ab801d


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:13:27:23
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:13:27:26
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2028,i,12579888137249560955,8188856835202488069,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:13:27:29
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://content.app-us1.com/0NYgQp/2024/09/30/f62cd38e-3ab7-407f-9dfb-0793c050f88f.pdf&c=E,1,xQip6Na2MSTVDIjYv9M8Bj8impmUH4TIHmI1fwI5zGIl9HrKNPslTUG-35BJfglZnIUdOxJMe0ijOxJCHd6ln_zfbAdsKmSTP_OUNXA-rC-M&typo=1"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly