Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es

Overview

General Information

Sample URL:https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
Analysis ID:1524407
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 5164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2668 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1980,i,6529807424552940528,5714558392947146128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6392 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.4:52355 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /www.schmidt-bretten.es?domain=schmidt-bretten.es HTTP/1.1Host: serviciodecorreo.esConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: serviciodecorreo.esConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: serviciodecorreo.es
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 02 Oct 2024 16:21:30 GMTContent-Type: text/htmlContent-Length: 548Connection: closeX-Server-Index: lp-mail-web-12
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 02 Oct 2024 16:21:30 GMTContent-Type: text/htmlContent-Length: 548Connection: closeX-Server-Index: lp-mail-web-12
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 52361 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52361
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49750 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@6/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1980,i,6529807424552940528,5714558392947146128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1980,i,6529807424552940528,5714558392947146128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    serviciodecorreo.es
    82.223.190.234
    truefalse
      unknown
      www.google.com
      142.250.185.68
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          171.39.242.20.in-addr.arpa
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://serviciodecorreo.es/favicon.icofalse
              unknown
              https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.esfalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.185.68
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.185.100
                unknownUnited States
                15169GOOGLEUSfalse
                82.223.190.234
                serviciodecorreo.esSpain
                8560ONEANDONE-ASBrauerstrasse48DEfalse
                IP
                192.168.2.4
                192.168.2.6
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1524407
                Start date and time:2024-10-02 18:20:32 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 7s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/4@6/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.185.195, 142.250.181.238, 74.125.71.84, 34.104.35.123, 20.114.59.183, 199.232.210.172, 192.229.221.95, 40.69.42.241, 52.165.164.15, 20.242.39.171, 13.85.23.86, 216.58.206.35, 199.232.214.172
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):548
                Entropy (8bit):4.688532577858027
                Encrypted:false
                SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                MD5:370E16C3B7DBA286CFF055F93B9A94D8
                SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                Malicious:false
                Reputation:low
                URL:https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):548
                Entropy (8bit):4.688532577858027
                Encrypted:false
                SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                MD5:370E16C3B7DBA286CFF055F93B9A94D8
                SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                Malicious:false
                Reputation:low
                URL:https://serviciodecorreo.es/favicon.ico
                Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Oct 2, 2024 18:21:26.513322115 CEST49675443192.168.2.4173.222.162.32
                Oct 2, 2024 18:21:29.367326021 CEST49742443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.367342949 CEST4434974282.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.367407084 CEST49742443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.367799044 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.367820978 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.367873907 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.368100882 CEST49742443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.368113995 CEST4434974282.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.368311882 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.368326902 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.389822960 CEST4434974282.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.389889002 CEST49742443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.390037060 CEST49742443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.390044928 CEST4434974282.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.390379906 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.390404940 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:29.390482903 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.390758038 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:29.390775919 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.057050943 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.057409048 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.057427883 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.058290005 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.058367014 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.060188055 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.060247898 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.060553074 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.060559988 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.094821930 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.095132113 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.095163107 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.096669912 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.096745014 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.097171068 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.097254038 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.109214067 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.139929056 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.139940023 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.186425924 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.448046923 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.448226929 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.448283911 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.456995964 CEST49743443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.457015991 CEST4434974382.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.734587908 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:30.779401064 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.939830065 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.940021992 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:30.940090895 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:31.373786926 CEST49744443192.168.2.482.223.190.234
                Oct 2, 2024 18:21:31.373814106 CEST4434974482.223.190.234192.168.2.4
                Oct 2, 2024 18:21:32.005831003 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.005954027 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.006038904 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.006764889 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.006808043 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.698930979 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.702142954 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.702166080 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.703612089 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.703702927 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.705245972 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.705498934 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.762181044 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:32.762195110 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:32.769329071 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:32.769387960 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:32.769782066 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:32.778354883 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:32.778374910 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:32.809063911 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:33.533081055 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.533149004 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.536353111 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.536364079 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.536592007 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.572838068 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.615442038 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.814464092 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.814532042 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.814589024 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.814673901 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.814701080 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.814714909 CEST49749443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.814722061 CEST44349749184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.858906984 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.858947992 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:33.859009027 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.859399080 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:33.859411955 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.525211096 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.525274992 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.531230927 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.531239986 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.531450033 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.540796041 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.583406925 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.808676958 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.808751106 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.808804035 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.809564114 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.809580088 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:34.809622049 CEST49750443192.168.2.4184.28.90.27
                Oct 2, 2024 18:21:34.809627056 CEST44349750184.28.90.27192.168.2.4
                Oct 2, 2024 18:21:42.585189104 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:42.585289955 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:42.585347891 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:44.142700911 CEST49747443192.168.2.4142.250.185.68
                Oct 2, 2024 18:21:44.142740011 CEST44349747142.250.185.68192.168.2.4
                Oct 2, 2024 18:21:55.255264997 CEST5235553192.168.2.4162.159.36.2
                Oct 2, 2024 18:21:55.260133028 CEST5352355162.159.36.2192.168.2.4
                Oct 2, 2024 18:21:55.260205984 CEST5235553192.168.2.4162.159.36.2
                Oct 2, 2024 18:21:55.260273933 CEST5235553192.168.2.4162.159.36.2
                Oct 2, 2024 18:21:55.265333891 CEST5352355162.159.36.2192.168.2.4
                Oct 2, 2024 18:21:55.703232050 CEST5352355162.159.36.2192.168.2.4
                Oct 2, 2024 18:21:55.704372883 CEST5235553192.168.2.4162.159.36.2
                Oct 2, 2024 18:21:55.709989071 CEST5352355162.159.36.2192.168.2.4
                Oct 2, 2024 18:21:55.710212946 CEST5235553192.168.2.4162.159.36.2
                Oct 2, 2024 18:22:32.030986071 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:32.031053066 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.031364918 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:32.031857967 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:32.031872034 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.661329985 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.661778927 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:32.661817074 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.662286997 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.662683964 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:32.662758112 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:32.715933084 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:33.138394117 CEST4972380192.168.2.493.184.221.240
                Oct 2, 2024 18:22:33.138696909 CEST4972580192.168.2.493.184.221.240
                Oct 2, 2024 18:22:33.143764019 CEST804972393.184.221.240192.168.2.4
                Oct 2, 2024 18:22:33.143826962 CEST4972380192.168.2.493.184.221.240
                Oct 2, 2024 18:22:33.144855976 CEST804972593.184.221.240192.168.2.4
                Oct 2, 2024 18:22:33.145003080 CEST4972580192.168.2.493.184.221.240
                Oct 2, 2024 18:22:42.566282988 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:42.566427946 CEST44352361142.250.185.100192.168.2.4
                Oct 2, 2024 18:22:42.567799091 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:44.062227964 CEST52361443192.168.2.4142.250.185.100
                Oct 2, 2024 18:22:44.062269926 CEST44352361142.250.185.100192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Oct 2, 2024 18:21:27.612162113 CEST53521661.1.1.1192.168.2.4
                Oct 2, 2024 18:21:27.697797060 CEST53522151.1.1.1192.168.2.4
                Oct 2, 2024 18:21:28.845103025 CEST53573681.1.1.1192.168.2.4
                Oct 2, 2024 18:21:29.306045055 CEST6424553192.168.2.41.1.1.1
                Oct 2, 2024 18:21:29.306341887 CEST5615753192.168.2.41.1.1.1
                Oct 2, 2024 18:21:29.351164103 CEST53642451.1.1.1192.168.2.4
                Oct 2, 2024 18:21:29.461374044 CEST53561571.1.1.1192.168.2.4
                Oct 2, 2024 18:21:31.970887899 CEST5043853192.168.2.41.1.1.1
                Oct 2, 2024 18:21:31.971261978 CEST5598453192.168.2.41.1.1.1
                Oct 2, 2024 18:21:31.978413105 CEST53559841.1.1.1192.168.2.4
                Oct 2, 2024 18:21:31.979571104 CEST53504381.1.1.1192.168.2.4
                Oct 2, 2024 18:21:44.723237991 CEST138138192.168.2.4192.168.2.255
                Oct 2, 2024 18:21:45.771451950 CEST53650171.1.1.1192.168.2.4
                Oct 2, 2024 18:21:55.254507065 CEST5352012162.159.36.2192.168.2.4
                Oct 2, 2024 18:21:55.751631975 CEST5132453192.168.2.41.1.1.1
                Oct 2, 2024 18:21:55.759596109 CEST53513241.1.1.1192.168.2.4
                Oct 2, 2024 18:22:32.021866083 CEST6047553192.168.2.41.1.1.1
                Oct 2, 2024 18:22:32.028906107 CEST53604751.1.1.1192.168.2.4
                TimestampSource IPDest IPChecksumCodeType
                Oct 2, 2024 18:21:29.461450100 CEST192.168.2.41.1.1.1c231(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Oct 2, 2024 18:21:29.306045055 CEST192.168.2.41.1.1.10xb829Standard query (0)serviciodecorreo.esA (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:29.306341887 CEST192.168.2.41.1.1.10x9812Standard query (0)serviciodecorreo.es65IN (0x0001)false
                Oct 2, 2024 18:21:31.970887899 CEST192.168.2.41.1.1.10xbee8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:31.971261978 CEST192.168.2.41.1.1.10xc505Standard query (0)www.google.com65IN (0x0001)false
                Oct 2, 2024 18:21:55.751631975 CEST192.168.2.41.1.1.10x5809Standard query (0)171.39.242.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                Oct 2, 2024 18:22:32.021866083 CEST192.168.2.41.1.1.10xf05cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Oct 2, 2024 18:21:29.351164103 CEST1.1.1.1192.168.2.40xb829No error (0)serviciodecorreo.es82.223.190.234A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:31.978413105 CEST1.1.1.1192.168.2.40xc505No error (0)www.google.com65IN (0x0001)false
                Oct 2, 2024 18:21:31.979571104 CEST1.1.1.1192.168.2.40xbee8No error (0)www.google.com142.250.185.68A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:40.161169052 CEST1.1.1.1192.168.2.40xc75cNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:40.161169052 CEST1.1.1.1192.168.2.40xc75cNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:40.242491961 CEST1.1.1.1192.168.2.40x15e3No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Oct 2, 2024 18:21:40.242491961 CEST1.1.1.1192.168.2.40x15e3No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:53.439713001 CEST1.1.1.1192.168.2.40x978dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Oct 2, 2024 18:21:53.439713001 CEST1.1.1.1192.168.2.40x978dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                Oct 2, 2024 18:21:55.759596109 CEST1.1.1.1192.168.2.40x5809Name error (3)171.39.242.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
                Oct 2, 2024 18:22:32.028906107 CEST1.1.1.1192.168.2.40xf05cNo error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
                Oct 2, 2024 18:22:41.244016886 CEST1.1.1.1192.168.2.40xe973No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Oct 2, 2024 18:22:41.244016886 CEST1.1.1.1192.168.2.40xe973No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                • serviciodecorreo.es
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44974382.223.190.2344432668C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-10-02 16:21:30 UTC710OUTGET /www.schmidt-bretten.es?domain=schmidt-bretten.es HTTP/1.1
                Host: serviciodecorreo.es
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-10-02 16:21:30 UTC175INHTTP/1.1 404 Not Found
                Server: nginx
                Date: Wed, 02 Oct 2024 16:21:30 GMT
                Content-Type: text/html
                Content-Length: 548
                Connection: close
                X-Server-Index: lp-mail-web-12
                2024-10-02 16:21:30 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44974482.223.190.2344432668C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-10-02 16:21:30 UTC642OUTGET /favicon.ico HTTP/1.1
                Host: serviciodecorreo.es
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-10-02 16:21:30 UTC175INHTTP/1.1 404 Not Found
                Server: nginx
                Date: Wed, 02 Oct 2024 16:21:30 GMT
                Content-Type: text/html
                Content-Length: 548
                Connection: close
                X-Server-Index: lp-mail-web-12
                2024-10-02 16:21:30 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449749184.28.90.27443
                TimestampBytes transferredDirectionData
                2024-10-02 16:21:33 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-10-02 16:21:33 UTC466INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (lpl/EF06)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-neu-z1
                Cache-Control: public, max-age=87857
                Date: Wed, 02 Oct 2024 16:21:33 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.449750184.28.90.27443
                TimestampBytes transferredDirectionData
                2024-10-02 16:21:34 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-10-02 16:21:34 UTC514INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (lpl/EF06)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-weu-z1
                Cache-Control: public, max-age=87800
                Date: Wed, 02 Oct 2024 16:21:34 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-10-02 16:21:34 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:12:21:22
                Start date:02/10/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:12:21:26
                Start date:02/10/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2020 --field-trial-handle=1980,i,6529807424552940528,5714558392947146128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:12:21:28
                Start date:02/10/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://serviciodecorreo.es/www.schmidt-bretten.es?domain=schmidt-bretten.es"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly