Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://webmail.schmidt-bretten.es/www.schmidt-bretten.es

Overview

General Information

Sample URL:http://webmail.schmidt-bretten.es/www.schmidt-bretten.es
Analysis ID:1524402
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 1536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5856 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2192,i,16061328214442360496,15235665194551479058,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 3636 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webmail.schmidt-bretten.es/www.schmidt-bretten.es" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /www.schmidt-bretten.es?domain=schmidt-bretten.es HTTP/1.1Host: serviciodecorreo.esConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: serviciodecorreo.esConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /www.schmidt-bretten.es HTTP/1.1Host: webmail.schmidt-bretten.esConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: webmail.schmidt-bretten.es
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: serviciodecorreo.es
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 02 Oct 2024 16:12:47 GMTContent-Type: text/htmlContent-Length: 548Connection: closeX-Server-Index: lp-mail-web-12
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 02 Oct 2024 16:12:48 GMTContent-Type: text/htmlContent-Length: 548Connection: closeX-Server-Index: lp-mail-web-12
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/10@6/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2192,i,16061328214442360496,15235665194551479058,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webmail.schmidt-bretten.es/www.schmidt-bretten.es"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2192,i,16061328214442360496,15235665194551479058,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    serviciodecorreo.es
    82.223.190.234
    truefalse
      unknown
      www.google.com
      216.58.206.36
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          webmail.schmidt-bretten.es
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://serviciodecorreo.es/favicon.icofalse
              unknown
              https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esfalse
                unknown
                http://webmail.schmidt-bretten.es/www.schmidt-bretten.esfalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.206.36
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  82.223.190.234
                  serviciodecorreo.esSpain
                  8560ONEANDONE-ASBrauerstrasse48DEfalse
                  IP
                  192.168.2.5
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1524402
                  Start date and time:2024-10-02 18:11:38 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 25s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://webmail.schmidt-bretten.es/www.schmidt-bretten.es
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:7
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@17/10@6/4
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.186.78, 173.194.76.84, 34.104.35.123, 199.232.214.172, 20.114.59.183, 192.229.221.95, 40.69.42.241, 20.3.187.198, 142.250.181.227
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://webmail.schmidt-bretten.es/www.schmidt-bretten.es
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:12:42 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2677
                  Entropy (8bit):3.986823339752883
                  Encrypted:false
                  SSDEEP:48:8SdahsT6yh5H+idAKZdA19ehwiZUklqehTy+3:8UP6oy
                  MD5:AD581788AD9CB62DE0E7A6CA7203CC51
                  SHA1:15FCB6C1ADF85611A45E9F76CF24BB616FCBBA42
                  SHA-256:AF114555064E2B692D215CD535FFF950D56BD32637CFCBF5450B5B399E10EA68
                  SHA-512:8128414914BEF4B436A3E80F9DC253F245C5C8DC8E973BC65C0312809D27688849AF3174863C144431341F02C214394934586CD5412F91FB80CFA0B7DE8E9046
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,.....?......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:12:42 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2679
                  Entropy (8bit):3.999245048309101
                  Encrypted:false
                  SSDEEP:48:8cdahsT6yh5H+idAKZdA1weh/iZUkAQkqehYy+2:8CPQ9Q1y
                  MD5:572822BDB339AB03C90801553638D661
                  SHA1:0E8DBFBD499827BE871D59F5E1E6433387C947D7
                  SHA-256:56C046DA94718A7A67C89D527F07AF8A78BD5636E23AEFB254F206CA8D4AFD41
                  SHA-512:0686E81ED57F12C97228BC3AD273BF587768484CDF481833A9ECE196F2DB9E69CD1FD626C3A4F91CF761B3919588A8E25E2E4B3F977D484B95DFC202DFA0A7BE
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2693
                  Entropy (8bit):4.009813118944318
                  Encrypted:false
                  SSDEEP:48:8xCdahsT6yhsH+idAKZdA14tseh7sFiZUkmgqeh7sSy+BX:8xEP3nsy
                  MD5:A815CD1F89791690BAA3370380E68636
                  SHA1:AE1E13C2534047FC643A14AA9F00E7035C83D50E
                  SHA-256:013B800B3795A7CC3BB1B9416C6752F7607D25480416B529F7D38693181018B8
                  SHA-512:2CB2BAF9F20BBEC7C29C99BD73FAC053850EE04B555FB9799CCD2CB3CBDF01B61850307082483EE43FAC225B2298AD27C5636CD6BD4335D6057902023234539A
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:12:42 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2681
                  Entropy (8bit):3.9974687603690575
                  Encrypted:false
                  SSDEEP:48:8adahsT6yh5H+idAKZdA1vehDiZUkwqeh0y+R:88P7ay
                  MD5:5F3458D46DD26EF98FF20CB955A1C2A6
                  SHA1:1BB634588CD6FB38C7595B570D630909C5A6B519
                  SHA-256:4E1C089CF504923818FF9B6BE16069653F814E25A69B831A2FE9E7168880A115
                  SHA-512:C426003414CF379721B6C821B63141D1886EF44E4C19F533E92FABA472EA31BFF451FCD03466C98AC9817C6879737AF402EA2A02054266A4BE5EEB8052DD5B38
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,...._h......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:12:42 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2681
                  Entropy (8bit):3.986780355432006
                  Encrypted:false
                  SSDEEP:48:8XudahsT6yh5H+idAKZdA1hehBiZUk1W1qehGy+C:8IPb9my
                  MD5:988FDEC26C8D5DD6E99901B8910B61B2
                  SHA1:320C01C302FB408226B695B7C0875FB9BD19C0AF
                  SHA-256:9155072229B132C45F7A96FA5A42A3FE2B92443DF6C2F56E439A8553E93B5CB2
                  SHA-512:4BA185333B4F40023595994CF3746AE1D6ADACCDC331BC95013615E03592FF841FA6D29FCD57FA310844C0AD5A0306A88CFE21E6B5F66C8C898F889B5D51AE9C
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:12:42 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                  Category:dropped
                  Size (bytes):2683
                  Entropy (8bit):3.997628939036678
                  Encrypted:false
                  SSDEEP:48:8IedahsT6yh5H+idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbsy+yT+:8IIP7T/TbxWOvTbsy7T
                  MD5:C00A609E70A554F9A48A7F78D3491E11
                  SHA1:BDA7518072899E40141FC047FD45C40C39283E79
                  SHA-256:56681C7647CE6888B8B28FD3B3D4FDD9BEF6062AFD502FAD4DD4D11714DA5F4C
                  SHA-512:B079B8AC97CF5AA00CE7D0A08B8E93E4E29831B83F02BD006CF6FFF4BA295926D1142A5C2061CB7CAD6EE226B5A39EA8BB335D723EEFDC9C117E28B9C7579647
                  Malicious:false
                  Reputation:low
                  Preview:L..................F.@.. ...$+.,.....}......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IBY......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VBY......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VBY......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VBY............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VBY.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............=.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with CRLF line terminators
                  Category:downloaded
                  Size (bytes):548
                  Entropy (8bit):4.688532577858027
                  Encrypted:false
                  SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                  MD5:370E16C3B7DBA286CFF055F93B9A94D8
                  SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                  SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                  SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                  Malicious:false
                  Reputation:low
                  URL:https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                  Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with CRLF line terminators
                  Category:downloaded
                  Size (bytes):548
                  Entropy (8bit):4.688532577858027
                  Encrypted:false
                  SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                  MD5:370E16C3B7DBA286CFF055F93B9A94D8
                  SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                  SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                  SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                  Malicious:false
                  Reputation:low
                  URL:https://serviciodecorreo.es/favicon.ico
                  Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 2, 2024 18:12:31.095722914 CEST49674443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:31.095866919 CEST49675443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:31.439565897 CEST49673443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:40.705065966 CEST49675443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:40.736318111 CEST49674443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:41.095699072 CEST49673443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:42.788758993 CEST4434970323.1.237.91192.168.2.5
                  Oct 2, 2024 18:12:42.788861990 CEST49703443192.168.2.523.1.237.91
                  Oct 2, 2024 18:12:44.430660009 CEST4971080192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:44.431279898 CEST4971180192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:44.436007023 CEST804971082.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:44.436419010 CEST804971182.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:44.436511040 CEST4971080192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:44.436518908 CEST4971180192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:44.436860085 CEST4971180192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:44.441987991 CEST804971182.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:45.088900089 CEST804971182.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:45.140074015 CEST4971180192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.120295048 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.120398998 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.120587111 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.121109962 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.121149063 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.161539078 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.161603928 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.161722898 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.162570953 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.162604094 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.793412924 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.800877094 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.800913095 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.802078009 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.802175045 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.812956095 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.813153982 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.856841087 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.858009100 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.858042955 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.859085083 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.859168053 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.867158890 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.867182970 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:46.875072956 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.875168085 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.875360966 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:46.875379086 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:46.915648937 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:46.915733099 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.156472921 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:47.156562090 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:47.156610966 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.157735109 CEST49714443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.157747984 CEST4434971482.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:47.248306990 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:47.248373032 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:47.248442888 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:47.249937057 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:47.249950886 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:47.821252108 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.821302891 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:47.821365118 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.822221994 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:47.822237015 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:47.890774965 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:47.890872955 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:47.904680014 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:47.904733896 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:47.905096054 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:47.959990978 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.494098902 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.586615086 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:48.586638927 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.587315083 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.587862015 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:48.587943077 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.588109970 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:48.632149935 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.635402918 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.675410986 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:48.796439886 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.796535015 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.796721935 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:48.817487001 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:48.817568064 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:48.817640066 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.819935083 CEST49716443192.168.2.582.223.190.234
                  Oct 2, 2024 18:12:48.819960117 CEST4434971682.223.190.234192.168.2.5
                  Oct 2, 2024 18:12:48.822333097 CEST49715443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.822374105 CEST44349715184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:48.953821898 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.953869104 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:48.954114914 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.954629898 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:48.954648972 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.592221022 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.592303991 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.597435951 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.597451925 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.597688913 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.598728895 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.643403053 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.867248058 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.867335081 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.867430925 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.868710041 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.868733883 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:49.868748903 CEST49717443192.168.2.5184.28.90.27
                  Oct 2, 2024 18:12:49.868762016 CEST44349717184.28.90.27192.168.2.5
                  Oct 2, 2024 18:12:56.711973906 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:56.712119102 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:12:56.712172031 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:57.590847969 CEST49713443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:12:57.590892076 CEST44349713216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:29.444139957 CEST4971080192.168.2.582.223.190.234
                  Oct 2, 2024 18:13:29.449172020 CEST804971082.223.190.234192.168.2.5
                  Oct 2, 2024 18:13:30.100398064 CEST4971180192.168.2.582.223.190.234
                  Oct 2, 2024 18:13:30.105601072 CEST804971182.223.190.234192.168.2.5
                  Oct 2, 2024 18:13:45.008529902 CEST804971082.223.190.234192.168.2.5
                  Oct 2, 2024 18:13:45.009366989 CEST4971080192.168.2.582.223.190.234
                  Oct 2, 2024 18:13:45.859008074 CEST4971080192.168.2.582.223.190.234
                  Oct 2, 2024 18:13:45.859939098 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:45.860004902 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:45.860074043 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:45.860450983 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:45.860467911 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:45.863883018 CEST804971082.223.190.234192.168.2.5
                  Oct 2, 2024 18:13:46.519795895 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:46.529449940 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:46.529464960 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:46.529800892 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:46.531043053 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:46.531104088 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:46.584633112 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:56.417347908 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:56.417414904 CEST44349727216.58.206.36192.168.2.5
                  Oct 2, 2024 18:13:56.417723894 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:57.570499897 CEST49727443192.168.2.5216.58.206.36
                  Oct 2, 2024 18:13:57.570559978 CEST44349727216.58.206.36192.168.2.5
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 2, 2024 18:12:41.419281960 CEST53517111.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:41.420305967 CEST53604841.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:42.428178072 CEST53496451.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:44.165460110 CEST5894453192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:44.165616035 CEST5409853192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:44.411248922 CEST53540981.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:44.428123951 CEST53589441.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:45.577740908 CEST6043053192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:45.578238964 CEST5022953192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:45.584650993 CEST53604301.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:45.585252047 CEST53502291.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:46.108782053 CEST5892353192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:46.113945961 CEST5047153192.168.2.51.1.1.1
                  Oct 2, 2024 18:12:46.153158903 CEST53589231.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:46.160321951 CEST53504711.1.1.1192.168.2.5
                  Oct 2, 2024 18:12:59.604918003 CEST53537541.1.1.1192.168.2.5
                  Oct 2, 2024 18:13:18.452918053 CEST53602761.1.1.1192.168.2.5
                  Oct 2, 2024 18:13:40.987027884 CEST53599841.1.1.1192.168.2.5
                  Oct 2, 2024 18:13:41.407921076 CEST53531811.1.1.1192.168.2.5
                  Oct 2, 2024 18:14:08.514631987 CEST53522861.1.1.1192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Oct 2, 2024 18:12:44.165460110 CEST192.168.2.51.1.1.10x2824Standard query (0)webmail.schmidt-bretten.esA (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:44.165616035 CEST192.168.2.51.1.1.10x9879Standard query (0)webmail.schmidt-bretten.es65IN (0x0001)false
                  Oct 2, 2024 18:12:45.577740908 CEST192.168.2.51.1.1.10x2ebcStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:45.578238964 CEST192.168.2.51.1.1.10x8c3cStandard query (0)www.google.com65IN (0x0001)false
                  Oct 2, 2024 18:12:46.108782053 CEST192.168.2.51.1.1.10x610cStandard query (0)serviciodecorreo.esA (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:46.113945961 CEST192.168.2.51.1.1.10xdc48Standard query (0)serviciodecorreo.es65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Oct 2, 2024 18:12:44.411248922 CEST1.1.1.1192.168.2.50x9879No error (0)webmail.schmidt-bretten.esserviciodecorreo.esCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:12:44.428123951 CEST1.1.1.1192.168.2.50x2824No error (0)webmail.schmidt-bretten.esserviciodecorreo.esCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:12:44.428123951 CEST1.1.1.1192.168.2.50x2824No error (0)serviciodecorreo.es82.223.190.234A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:45.584650993 CEST1.1.1.1192.168.2.50x2ebcNo error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:45.585252047 CEST1.1.1.1192.168.2.50x8c3cNo error (0)www.google.com65IN (0x0001)false
                  Oct 2, 2024 18:12:46.153158903 CEST1.1.1.1192.168.2.50x610cNo error (0)serviciodecorreo.es82.223.190.234A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:52.036384106 CEST1.1.1.1192.168.2.50x66e6No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:52.036384106 CEST1.1.1.1192.168.2.50x66e6No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:12:52.560540915 CEST1.1.1.1192.168.2.50x566bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:12:52.560540915 CEST1.1.1.1192.168.2.50x566bNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:13:07.611494064 CEST1.1.1.1192.168.2.50x2152No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:13:07.611494064 CEST1.1.1.1192.168.2.50x2152No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:13:33.531594038 CEST1.1.1.1192.168.2.50x54fbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:13:33.531594038 CEST1.1.1.1192.168.2.50x54fbNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  Oct 2, 2024 18:13:54.001029968 CEST1.1.1.1192.168.2.50xc672No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Oct 2, 2024 18:13:54.001029968 CEST1.1.1.1192.168.2.50xc672No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  • serviciodecorreo.es
                  • https:
                  • fs.microsoft.com
                  • webmail.schmidt-bretten.es
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.54971182.223.190.234805856C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 2, 2024 18:12:44.436860085 CEST463OUTGET /www.schmidt-bretten.es HTTP/1.1
                  Host: webmail.schmidt-bretten.es
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Oct 2, 2024 18:12:45.088900089 CEST438INHTTP/1.1 301 Moved Permanently
                  Server: nginx
                  Date: Wed, 02 Oct 2024 16:12:44 GMT
                  Content-Type: text/html
                  Content-Length: 162
                  Connection: keep-alive
                  Location: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                  X-Server-Index: lp-mail-web-12
                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
                  Oct 2, 2024 18:13:30.100398064 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.54971082.223.190.234805856C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 2, 2024 18:13:29.444139957 CEST6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.54971482.223.190.2344435856C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-02 16:12:46 UTC710OUTGET /www.schmidt-bretten.es?domain=schmidt-bretten.es HTTP/1.1
                  Host: serviciodecorreo.es
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-10-02 16:12:47 UTC175INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Wed, 02 Oct 2024 16:12:47 GMT
                  Content-Type: text/html
                  Content-Length: 548
                  Connection: close
                  X-Server-Index: lp-mail-web-12
                  2024-10-02 16:12:47 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                  Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.54971682.223.190.2344435856C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-02 16:12:48 UTC642OUTGET /favicon.ico HTTP/1.1
                  Host: serviciodecorreo.es
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-10-02 16:12:48 UTC175INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Wed, 02 Oct 2024 16:12:48 GMT
                  Content-Type: text/html
                  Content-Length: 548
                  Connection: close
                  X-Server-Index: lp-mail-web-12
                  2024-10-02 16:12:48 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                  Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.549715184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-10-02 16:12:48 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-10-02 16:12:48 UTC466INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-neu-z1
                  Cache-Control: public, max-age=88382
                  Date: Wed, 02 Oct 2024 16:12:48 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.549717184.28.90.27443
                  TimestampBytes transferredDirectionData
                  2024-10-02 16:12:49 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-10-02 16:12:49 UTC514INHTTP/1.1 200 OK
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (lpl/EF06)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-weu-z1
                  Cache-Control: public, max-age=88325
                  Date: Wed, 02 Oct 2024 16:12:49 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-10-02 16:12:49 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:12:12:34
                  Start date:02/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:12:12:39
                  Start date:02/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2192,i,16061328214442360496,15235665194551479058,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:12:12:43
                  Start date:02/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://webmail.schmidt-bretten.es/www.schmidt-bretten.es"
                  Imagebase:0x7ff715980000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly