Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/

Overview

General Information

Sample URL:https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/
Analysis ID:1528313
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6528 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 4536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1920,i,503674260585812908,14686945758166603473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 5328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/SlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering
Source: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.18:49704 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.18:49694 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XyOUlSAShXTp3fn&MD=ZDLSgA7Z HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficDNS traffic detected: DNS query: 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlDate: Mon, 07 Oct 2024 17:11:50 GMTServer: NetlifyStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Nf-Request-Id: 01J9KZEGBDQ4QMSG7YXM667CWMConnection: closeTransfer-Encoding: chunked
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: private, max-age=0Content-Type: text/plain; charset=utf-8Date: Mon, 07 Oct 2024 17:11:50 GMTServer: NetlifyStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Nf-Request-Id: 01J9KZEGK9D9DGQWFHENT837C2Content-Length: 50Connection: close
Source: chromecache_49.2.drString found in binary or memory: https://answers.netlify.com/t/support-guide-i-ve-deployed-my-site-but-i-still-see-page-not-found/125
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.18:49704 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/10@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1920,i,503674260585812908,14686945758166603473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1920,i,503674260585812908,14686945758166603473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.1.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.132
truefalse
    unknown
    66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app
    3.72.140.173
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/true
        unknown
        https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/favicon.icotrue
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          https://answers.netlify.com/t/support-guide-i-ve-deployed-my-site-but-i-still-see-page-not-found/125chromecache_49.2.drfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            3.72.140.173
            66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.appUnited States
            16509AMAZON-02USfalse
            142.250.185.132
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.18
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1528313
            Start date and time:2024-10-07 19:11:18 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 44s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:defaultwindowsinteractivecookbook.jbs
            Sample URL:https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:11
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal48.win@16/10@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.184.238, 172.253.115.84, 34.104.35.123, 93.184.221.240
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/
            No simulations
            InputOutput
            URL: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/ Model: jbxai
            "{
               \"brand\": [\"Netlify\"],
               \"contains_trigger_text\": false,
               \"trigger_text\": \"\",
               \"prominent_button_name\": \"Back to our site\",
               \"text_input_field_labels\": \"unknown\",
               \"pdf_icon_visible\": false,
               \"has_visible_captcha\": false,
               \"has_urgent_text\": false,
               \"text\": \"Site Not Found Looks like you've followed a broken link or entered a URL that doesn't exist on Netlify. If this is your site,
             and you weren't expecting a 404 for this path,
             please visit Netlify's \"page not found\" support guide for troubleshooting tips. Netlify Internal ID: 01J9KZEGBDQ4QMSG7YXM667CWM\" }
            "
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:11:49 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2675
            Entropy (8bit):3.968893787690705
            Encrypted:false
            SSDEEP:48:8DJd6T5m1NHEUidAKZdA1rehwiZUklqeh3y+3:8DuVm1H8y
            MD5:AF2260B1C3707F9764F7FEDCCAB913F1
            SHA1:BB73ECC3F1D23398C9A1B963B4D2A1E3DF0A6C92
            SHA-256:B81D4093411A5219219C9E9C4C636A84A7031C1A2FED4206442631FC0463A222
            SHA-512:546361E2A888469EE8894AA7985162BADD510A198619003842C79771BAE0F8C8CB54FE0806C9D3F55DE0368107D97712D87E1C0322FEF0E24B4810276CAC869D
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....|3O.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VGYy......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:11:49 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2677
            Entropy (8bit):3.9849556673227147
            Encrypted:false
            SSDEEP:48:83Jd6T5m1NHEUidAKZdA1ceh/iZUkAQkqehsy+2:83uVm1T9Qly
            MD5:527AF394C696EC757BC514C0370B3723
            SHA1:D36C12D976F87776B5A3413B8E7C9D5D52DD6E93
            SHA-256:4155F4C756FEFADCF4AD0BEDADB429C35F522811407462E5151EA722937DFCAD
            SHA-512:578AA6BF65AFFBE3D00FFDC13EC30B41E5A6224217237467650C1EDACE02E8536D76661DCF3C9BCB284D8392A607CBD9C989749D2E1A2385FCB9930C91BCA73A
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....5;B.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VGYy......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2691
            Entropy (8bit):3.9952332611629164
            Encrypted:false
            SSDEEP:48:8XRJd6T5m1SHEUidAKZdA14Aeh7sFiZUkmgqeh7syy+BX:8huVm1kngy
            MD5:BC03AA055A0A8AF12269DEE36EF844F5
            SHA1:EEE6534BBC5480E4712AD4A53C82009FC8456366
            SHA-256:532682821208C880E57BB977F0184FD8A51085691E30E873E6F2C16CB994A00E
            SHA-512:89365216040246F545F5BB24AFB7D0077A4673153CE6623C1D2066751B75A96B68FC6B235DBC528689D7DA2DE55A14A010103B9EE5E667FDBD1BC3C3D84F30C6
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....?.4 ?.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.R.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:11:49 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.9829798581880684
            Encrypted:false
            SSDEEP:48:8tJd6T5m1NHEUidAKZdA1JehDiZUkwqeh4y+R:8tuVm1eKy
            MD5:CA678593E2405BD518F21CB88AECAD08
            SHA1:F03DF6D314A01CF0F91A4059A18A820C259D32C4
            SHA-256:CD5767A662034D7B784541A74F2F883D8C86FE35E36799B864B548E12569CD10
            SHA-512:690603AC37F8ADDF509C2D39B46651366B813E1BC71B3E581FED00D53A43DB379DC25D467D2F7B254310466CB7A05E7281E8CCEB23C94B89A5A3A94A25DAA47D
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,....f.;.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VGYy......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:11:49 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2679
            Entropy (8bit):3.972627780301279
            Encrypted:false
            SSDEEP:48:8VJd6T5m1NHEUidAKZdA1XehBiZUk1W1qehmy+C:8VuVm1+9Gy
            MD5:4FCF343B15B36D03E8361E7F89DB3C43
            SHA1:EA8A2D7A774EF575865640379052575195A80191
            SHA-256:66B7F01983753B3B7A57C9E1EA2C0CDBBB6AE9E4D93FF173852D6C183D2BC2BF
            SHA-512:90F7F434D9049EB72FE96AF53809848DE94EB390466EB65CAAB7C1F9DCC59B8E7CB0D2D4AA29AB4158C7E985FAC062D7655B835A3C24919A4DF18AD91B377270
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,.....|H.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VGYy......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:11:49 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):3.983088671660835
            Encrypted:false
            SSDEEP:48:8BJd6T5m1NHEUidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbgy+yT+:8BuVm1yT/TbxWOvTbgy7T
            MD5:4E5839A5FDBED3C9C5D26C417D1BF4CF
            SHA1:29E7FB202C52307F122BF75C66C2FF90A87D40AB
            SHA-256:DCCEA8EE98414367FD1048A7F58C540EED0FEEA95D179D989FE1817B5772CD1C
            SHA-512:D0171C0557CFC1BF0AE971845170F8AAE4612CBE2B16ABD69DCB6072738DB55A473C8BAE7B4E6AB760B36AFB25582C3AD8FEC71AE669A1DA39C9EE8F854DD8DF
            Malicious:false
            Reputation:low
            Preview:L..................F.@.. ...$+.,......2.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.IGYp.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VGYx.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.VGYx.....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.VGYx............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VGYy......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........;..R.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with very long lines (1642)
            Category:downloaded
            Size (bytes):2768
            Entropy (8bit):5.519909620656247
            Encrypted:false
            SSDEEP:48:0rCTeIlUJ+0WfAd1QpED3qBTRnejUnyzpFJlQoPZUHotkhXPQWi/m:IIlEQpEUUXx/KoStPQO
            MD5:5DA607B0A5A5647AEF39AA15D0103847
            SHA1:EBE347E44F9F5D96D1367581D132F75657EFA220
            SHA-256:01F0619B95D9757E09FAB71E234AADD12F91578083FFD91C723252AB3686A8A8
            SHA-512:DF3E483A6800024116F0949F755B657695537D99F2924CAF5A54B70324D1566E3C37FF096A2DFB940384F7997DDAAF73E44336498AF332742B5E5EC06ACE69AA
            Malicious:false
            Reputation:low
            URL:https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/
            Preview:<!doctype html><meta charset=utf-8><meta name=viewport content="width=device-width,initial-scale=1,maximum-scale=1,user-scalable=no"><title>Site Not Found</title><style>:root{--colorDefaultTextColor:#A3A9AC;--colorDefaultTextColorCard:#2D3B41;--colorBgApp:rgb(14, 30, 37);--colorBgInverse:hsl(175, 48%, 98%);--colorTextMuted:rgb(100, 110, 115);--colorError:#D32254;--colorBgCard:#fff;--colorShadow:#0e1e251f;--colorErrorText:rgb(142, 11, 48);--colorCardTitleCard:#2D3B41;--colorStackText:#222;--colorCodeText:#F5F5F5}body{font-family:-apple-system,BlinkMacSystemFont,segoe ui,Roboto,Helvetica,Arial,sans-serif,apple color emoji,segoe ui emoji,segoe ui symbol;background:#34383c;color:#fff;overflow:hidden;margin:0;padding:0;font-size:1rem;line-height:1.5}h1{margin:0;font-size:1.375rem;line-height:1.2}.main{position:relative;display:flex;flex-direction:column;align-items:center;justify-content:center;height:100vh;width:100vw}.card{position:relative;display:flex;flex-direction:column;width:75%;max
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with no line terminators
            Category:downloaded
            Size (bytes):50
            Entropy (8bit):4.861467880199448
            Encrypted:false
            SSDEEP:3:ObynQA2cueyRj:ObPHcuLj
            MD5:FD3DE1BA21F98EA0AFE4E405B159748B
            SHA1:CAE308D9BA3FB74D6AB18BB15090CEDC9D079B59
            SHA-256:DA8C1E25EFD930AF71FA18F99970BCAEB9786873C12ACC7E2A891457DD1D287F
            SHA-512:F236FCC133A57F9A1624500ABAACC9B4BC1945DA04CB22D44CD9C72D0FAE0101C58C9237FEA02F9B3B43F6608F7421857F795E757D0AEBE3A999F9208082775F
            Malicious:false
            Reputation:low
            URL:https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/favicon.ico
            Preview:Not Found - Request ID: 01J9KZEGK9D9DGQWFHENT837C2
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 7, 2024 19:11:48.786067963 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:48.791115999 CEST53496941.1.1.1192.168.2.18
            Oct 7, 2024 19:11:48.791290998 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:48.791290998 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:48.791321039 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:48.796190023 CEST53496941.1.1.1192.168.2.18
            Oct 7, 2024 19:11:48.796204090 CEST53496941.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.390707016 CEST53496941.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.391211987 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:49.396641016 CEST53496941.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.396740913 CEST4969453192.168.2.181.1.1.1
            Oct 7, 2024 19:11:49.473511934 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.473541975 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:49.473601103 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.473849058 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.473902941 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:49.473949909 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.474041939 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.474056959 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:49.474337101 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:49.474354029 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.162782907 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.163410902 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.163422108 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.164407015 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.165450096 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.165450096 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.165515900 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.165622950 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.165630102 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.169408083 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.169774055 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.169785023 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.171009064 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.171075106 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.172008991 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.172075987 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.215137959 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.221987009 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.222023964 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.262510061 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.464472055 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.464528084 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.464606047 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.464728117 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.464728117 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.466847897 CEST49696443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.466869116 CEST443496963.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.540643930 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.587405920 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.714600086 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.714782953 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:50.715013027 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.715450048 CEST49697443192.168.2.183.72.140.173
            Oct 7, 2024 19:11:50.715473890 CEST443496973.72.140.173192.168.2.18
            Oct 7, 2024 19:11:52.892541885 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:52.892570019 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:52.892643929 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:52.894220114 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:52.894232035 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.514008999 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:53.514049053 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:53.514111996 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:53.514395952 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:53.514406919 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:53.673990965 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.674181938 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.679157972 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.679172039 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.679442883 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.723409891 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.771400928 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.942959070 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.943039894 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.943101883 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.943176031 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.943190098 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.943201065 CEST49701443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.943207026 CEST44349701184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.972290993 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.972345114 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:53.972455025 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.972784996 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:53.972799063 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:54.337332964 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:54.338177919 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:54.338190079 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:54.339237928 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:54.339309931 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:54.345212936 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:54.345304012 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:54.398468971 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:54.398487091 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:11:54.446465969 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:11:54.739123106 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:54.739208937 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:54.740551949 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:54.740564108 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:54.740806103 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:54.741941929 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:54.783412933 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:55.003700018 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:55.003915071 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:55.003998041 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:55.004858971 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:55.004878998 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:55.004890919 CEST49703443192.168.2.18184.28.90.27
            Oct 7, 2024 19:11:55.004898071 CEST44349703184.28.90.27192.168.2.18
            Oct 7, 2024 19:11:59.438940048 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:11:59.718348026 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:11:59.718405008 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:11:59.718554020 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:11:59.719810009 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:11:59.719827890 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:11:59.741605043 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:12:00.345504045 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:12:00.441103935 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.441184044 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.444065094 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.444073915 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.444461107 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.489526987 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.504995108 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.547391891 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748198032 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748222113 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748229980 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748239994 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748270035 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748347044 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.748372078 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748389006 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.748395920 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748403072 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748426914 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.748434067 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.748485088 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.760147095 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.760165930 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:00.760174990 CEST49704443192.168.2.1820.109.210.53
            Oct 7, 2024 19:12:00.760179996 CEST4434970420.109.210.53192.168.2.18
            Oct 7, 2024 19:12:01.554502010 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:12:03.964529037 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:12:04.157393932 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:12:04.157457113 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:12:04.157521963 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:12:04.924541950 CEST49702443192.168.2.18142.250.185.132
            Oct 7, 2024 19:12:04.924577951 CEST44349702142.250.185.132192.168.2.18
            Oct 7, 2024 19:12:06.567126036 CEST49679443192.168.2.1852.182.141.63
            Oct 7, 2024 19:12:06.870692015 CEST49679443192.168.2.1852.182.141.63
            Oct 7, 2024 19:12:07.481436968 CEST49679443192.168.2.1852.182.141.63
            Oct 7, 2024 19:12:08.693650961 CEST49679443192.168.2.1852.182.141.63
            Oct 7, 2024 19:12:08.773546934 CEST49673443192.168.2.18204.79.197.203
            Oct 7, 2024 19:12:11.104521990 CEST49679443192.168.2.1852.182.141.63
            Oct 7, 2024 19:12:15.912564993 CEST49679443192.168.2.1852.182.141.63
            TimestampSource PortDest PortSource IPDest IP
            Oct 7, 2024 19:11:48.747963905 CEST53600061.1.1.1192.168.2.18
            Oct 7, 2024 19:11:48.752677917 CEST53646271.1.1.1192.168.2.18
            Oct 7, 2024 19:11:48.752923965 CEST53555021.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.462965012 CEST5671353192.168.2.181.1.1.1
            Oct 7, 2024 19:11:49.463129997 CEST6029353192.168.2.181.1.1.1
            Oct 7, 2024 19:11:49.472945929 CEST53602931.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.472999096 CEST53567131.1.1.1192.168.2.18
            Oct 7, 2024 19:11:49.959037066 CEST53620961.1.1.1192.168.2.18
            Oct 7, 2024 19:11:53.505588055 CEST6413153192.168.2.181.1.1.1
            Oct 7, 2024 19:11:53.505589008 CEST5030653192.168.2.181.1.1.1
            Oct 7, 2024 19:11:53.512904882 CEST53503061.1.1.1192.168.2.18
            Oct 7, 2024 19:11:53.513178110 CEST53641311.1.1.1192.168.2.18
            Oct 7, 2024 19:12:06.974980116 CEST53647681.1.1.1192.168.2.18
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 7, 2024 19:11:49.462965012 CEST192.168.2.181.1.1.10x1e4fStandard query (0)66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.appA (IP address)IN (0x0001)false
            Oct 7, 2024 19:11:49.463129997 CEST192.168.2.181.1.1.10x5f5Standard query (0)66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app65IN (0x0001)false
            Oct 7, 2024 19:11:53.505588055 CEST192.168.2.181.1.1.10x3030Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 7, 2024 19:11:53.505589008 CEST192.168.2.181.1.1.10xf7fStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 7, 2024 19:11:49.472999096 CEST1.1.1.1192.168.2.180x1e4fNo error (0)66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app3.72.140.173A (IP address)IN (0x0001)false
            Oct 7, 2024 19:11:49.472999096 CEST1.1.1.1192.168.2.180x1e4fNo error (0)66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app3.70.101.28A (IP address)IN (0x0001)false
            Oct 7, 2024 19:11:53.512904882 CEST1.1.1.1192.168.2.180xf7fNo error (0)www.google.com65IN (0x0001)false
            Oct 7, 2024 19:11:53.513178110 CEST1.1.1.1192.168.2.180x3030No error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
            • 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app
            • https:
            • fs.microsoft.com
            • slscr.update.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.18496963.72.140.1734434536C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-07 17:11:50 UTC703OUTGET / HTTP/1.1
            Host: 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-07 17:11:50 UTC270INHTTP/1.1 404 Not Found
            Content-Type: text/html
            Date: Mon, 07 Oct 2024 17:11:50 GMT
            Server: Netlify
            Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
            X-Nf-Request-Id: 01J9KZEGBDQ4QMSG7YXM667CWM
            Connection: close
            Transfer-Encoding: chunked
            2024-10-07 17:11:50 UTC916INData Raw: 39 62 35 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 3e 3c 74 69 74 6c 65 3e 53 69 74 65 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 3a 72 6f 6f 74 7b 2d 2d 63 6f 6c 6f 72 44 65 66 61 75 6c 74 54 65 78 74 43 6f 6c 6f 72 3a 23 41 33 41 39 41 43 3b 2d 2d 63 6f 6c 6f 72 44 65 66 61 75 6c 74 54 65 78 74 43 6f 6c 6f 72 43 61 72 64 3a 23 32 44 33 42 34 31 3b 2d 2d 63 6f 6c 6f 72
            Data Ascii: 9b5<!doctype html><meta charset=utf-8><meta name=viewport content="width=device-width,initial-scale=1,maximum-scale=1,user-scalable=no"><title>Site Not Found</title><style>:root{--colorDefaultTextColor:#A3A9AC;--colorDefaultTextColorCard:#2D3B41;--color
            2024-10-07 17:11:50 UTC1871INData Raw: 30 30 76 68 3b 77 69 64 74 68 3a 31 30 30 76 77 7d 2e 63 61 72 64 7b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 66 6c 65 78 2d 64 69 72 65 63 74 69 6f 6e 3a 63 6f 6c 75 6d 6e 3b 77 69 64 74 68 3a 37 35 25 3b 6d 61 78 2d 77 69 64 74 68 3a 35 30 30 70 78 3b 70 61 64 64 69 6e 67 3a 32 34 70 78 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 63 6f 6c 6f 72 3a 23 30 65 31 65 32 35 3b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 38 70 78 3b 62 6f 78 2d 73 68 61 64 6f 77 3a 30 20 32 70 78 20 34 70 78 20 72 67 62 61 28 31 34 2c 33 30 2c 33 37 2c 2e 31 36 29 7d 61 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 36 30 30 3b 6c 69 6e 65 2d 68 65 69 67 68 74 3a 32 34 70 78 3b 63 6f 6c 6f 72 3a 23 30
            Data Ascii: 00vh;width:100vw}.card{position:relative;display:flex;flex-direction:column;width:75%;max-width:500px;padding:24px;background:#fff;color:#0e1e25;border-radius:8px;box-shadow:0 2px 4px rgba(14,30,37,.16)}a{margin:0;font-weight:600;line-height:24px;color:#0


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.18496973.72.140.1734434536C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-10-07 17:11:50 UTC676OUTGET /favicon.ico HTTP/1.1
            Host: 66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-10-07 17:11:50 UTC313INHTTP/1.1 404 Not Found
            Cache-Control: private, max-age=0
            Content-Type: text/plain; charset=utf-8
            Date: Mon, 07 Oct 2024 17:11:50 GMT
            Server: Netlify
            Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
            X-Nf-Request-Id: 01J9KZEGK9D9DGQWFHENT837C2
            Content-Length: 50
            Connection: close
            2024-10-07 17:11:50 UTC50INData Raw: 4e 6f 74 20 46 6f 75 6e 64 20 2d 20 52 65 71 75 65 73 74 20 49 44 3a 20 30 31 4a 39 4b 5a 45 47 4b 39 44 39 44 47 51 57 46 48 45 4e 54 38 33 37 43 32
            Data Ascii: Not Found - Request ID: 01J9KZEGK9D9DGQWFHENT837C2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.1849701184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-07 17:11:53 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-07 17:11:53 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF4C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=171252
            Date: Mon, 07 Oct 2024 17:11:53 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.1849703184.28.90.27443
            TimestampBytes transferredDirectionData
            2024-10-07 17:11:54 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-10-07 17:11:54 UTC515INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (lpl/EF06)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-weu-z1
            Cache-Control: public, max-age=171294
            Date: Mon, 07 Oct 2024 17:11:54 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-10-07 17:11:54 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.184970420.109.210.53443
            TimestampBytes transferredDirectionData
            2024-10-07 17:12:00 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XyOUlSAShXTp3fn&MD=ZDLSgA7Z HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
            Host: slscr.update.microsoft.com
            2024-10-07 17:12:00 UTC560INHTTP/1.1 200 OK
            Cache-Control: no-cache
            Pragma: no-cache
            Content-Type: application/octet-stream
            Expires: -1
            Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
            ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
            MS-CorrelationId: 6f6013fe-6f2f-427b-a305-c915627dcb92
            MS-RequestId: 581e6530-32a5-467d-8c0e-3b2bac35f53c
            MS-CV: ofTass6rs0mX/VZW.0
            X-Microsoft-SLSClientCache: 2880
            Content-Disposition: attachment; filename=environment.cab
            X-Content-Type-Options: nosniff
            Date: Mon, 07 Oct 2024 17:12:00 GMT
            Connection: close
            Content-Length: 24490
            2024-10-07 17:12:00 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
            Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
            2024-10-07 17:12:00 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
            Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:1
            Start time:13:11:46
            Start date:07/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff728d30000
            File size:3'242'272 bytes
            MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:13:11:47
            Start date:07/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1920,i,503674260585812908,14686945758166603473,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff728d30000
            File size:3'242'272 bytes
            MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:13:11:48
            Start date:07/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://66e41162be8b44fa4ef98165--lively-meringue-d6fcef.netlify.app/"
            Imagebase:0x7ff728d30000
            File size:3'242'272 bytes
            MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly