Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://aeat.es

Overview

General Information

Sample URL:http://aeat.es
Analysis ID:1528666
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3040 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5824 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1972,i,4360780461697686295,14656468667491634171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5660 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aeat.es" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficDNS traffic detected: DNS query: aeat.es
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@19/6@12/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1972,i,4360780461697686295,14656468667491634171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aeat.es"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1972,i,4360780461697686295,14656468667491634171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://aeat.es0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
www.google.com0%VirustotalBrowse
aeat.es0%VirustotalBrowse
s-part-0032.t-0009.t-msedge.net0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
google.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalseunknown
google.com
172.217.16.206
truefalseunknown
www.google.com
172.217.16.196
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
s-part-0032.t-0009.t-msedge.net
13.107.246.60
truefalseunknown
aeat.es
unknown
unknownfalseunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
239.255.255.250
unknownReserved
unknownunknownfalse
172.217.16.196
www.google.comUnited States
15169GOOGLEUSfalse
IP
192.168.2.5
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528666
Start date and time:2024-10-08 08:44:47 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:browseurl.jbs
Sample URL:http://aeat.es
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:UNKNOWN
Classification:unknown0.win@19/6@12/3
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • URL browsing timeout or error
  • URL not reachable
  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 142.250.186.131, 142.250.186.78, 108.177.15.84, 34.104.35.123, 184.28.90.27, 52.149.20.212, 199.232.214.172, 192.229.221.95, 40.69.42.241
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, azureedge-t-prod.trafficmanager.net, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtSetInformationFile calls found.
  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
No simulations
No context
No context
No context
No context
No context
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 05:45:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2677
Entropy (8bit):3.9806391198941062
Encrypted:false
SSDEEP:48:8fwdST+yWHwidAKZdA19ehwiZUklqehBy+3:81D1uy
MD5:B897E74AFBD6247608813494A8023CB6
SHA1:048CD5469EC159DB15F851002DB33D5D7A003D02
SHA-256:4DF98445394500495642672D68FEC2DE478FD48165763C05C3130B478E81368D
SHA-512:7AF6ACB15FDBC39E71EA06F2D953AB15F490071F094C4432B8996E6C04E36BA0053A38E9F42C59B0D3366F80A0283C6B8DB157B4CCCA5EAD6AE415A59B76E451
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,....(..M...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.5...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 05:45:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2679
Entropy (8bit):3.9952678097753003
Encrypted:false
SSDEEP:48:8DdST+yWHwidAKZdA1weh/iZUkAQkqehey+2:88Dv9QHy
MD5:CFE0C4BF50FD8A3B418F465F10E2C8BB
SHA1:3016A4E7D6122599D637D52CDBFC4D7F8CFCABE8
SHA-256:C1EDDAB3BB0BB742111F3258C8D8658668DE76A1F860E6F352D32DFFDA255CAF
SHA-512:20C05B69ECCBF8917F967D53FCAF18B4AEC3A75C7AF389FF64BF12101367B29E630B624A952C93ED551F1EC18CE5FDFFF6D155083C2E765663B9A245D2AE1FCD
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......M...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.5...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2693
Entropy (8bit):4.006119746424826
Encrypted:false
SSDEEP:48:8xzdST+ysHwidAKZdA14tseh7sFiZUkmgqeh7sEy+BX:8xMD9nCy
MD5:87342A87C26AF3A2FA9925731AF952C1
SHA1:442A011B62797630F985F5C10633C1CAA5DCB268
SHA-256:442F10820ADA9AD2B1324204D29776161520B6D3A0378D6E69579E19305F4DC0
SHA-512:485927D9A059704F465636CC73F057CE26717B7AC180CC762F92AFA865B11E025B3F582C3442D36E60F342CB474E6FEC9337303CE7A7E02C578BA82F1F6EF8EB
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 05:45:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2681
Entropy (8bit):3.9935239480947997
Encrypted:false
SSDEEP:48:8sdST+yWHwidAKZdA1vehDiZUkwqeh6y+R:8hDMcy
MD5:4E4811961B429C8B3BA50C4002A59730
SHA1:36B32BCB84BE03BD9233B9B4D4566988E50A429F
SHA-256:24EDFB4AD1D377B9ED4349B827C0EA7FE04F0481374C940DEC34FC6610F0C415
SHA-512:0528000080C1C3D94841314EF8F8969A32176A04053320A0F9B7CDE66C1A853526F7F188D822FC985BEA689CB7F9FB8B6ADCA3625DCD8FED0BB698F6E7580757
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,....V..M...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.5...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 05:45:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2681
Entropy (8bit):3.983570237758202
Encrypted:false
SSDEEP:48:8tdST+yWHwidAKZdA1hehBiZUk1W1qehYy+C:8yD894y
MD5:9B23422908282EA82322ECCEE6FB672B
SHA1:F96D54EAC5B3C58ABEBF68972327B0DF22152078
SHA-256:6659DF1A058C4ABB9FFCE19B2957A31B53C9882A43F686C4DB4829387631745D
SHA-512:2AFE8DFCE1686A665CABE3C3461DCEC3BD3BF92984A3D70BCC24CC47F0B11163BB08229E571C7D0277DC174CDEB809384BB1F51EF8445406F65516AEC2A29D83
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,........M...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.5...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
Process:C:\Program Files\Google\Chrome\Application\chrome.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 05:45:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
Category:dropped
Size (bytes):2683
Entropy (8bit):3.992789813118959
Encrypted:false
SSDEEP:48:8udST+yWHwidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbCy+yT+:8/DST/TbxWOvTbCy7T
MD5:A44C8579C88DC5ADA861A70E70169F7D
SHA1:2853A7C423C5BF9876388109E28A296A382456EB
SHA-256:12CEB0C07CD1118510769629DDC7BA2E08B69C83CBF3AA59B5540ECA59D2CCE3
SHA-512:E02C49B1344B94E8EBA9214CE35616A3D2F47C3BA8895E601D71A6D3F88995A9591610A5941F3B063C3BCC56A2ED9BED7A1055AB4BD8903BC65E7178E276AA65
Malicious:false
Reputation:low
Preview:L..................F.@.. ...$+.,........M...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IHY.5....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.5....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.5....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.5..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.5...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i.............S......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
No static file info
TimestampSource PortDest PortSource IPDest IP
Oct 8, 2024 08:45:34.308460951 CEST49675443192.168.2.523.1.237.91
Oct 8, 2024 08:45:34.324089050 CEST49674443192.168.2.523.1.237.91
Oct 8, 2024 08:45:34.417757988 CEST49673443192.168.2.523.1.237.91
Oct 8, 2024 08:45:43.678086996 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:43.678127050 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:43.682324886 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:43.682667971 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:43.682682991 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:43.921097994 CEST49675443192.168.2.523.1.237.91
Oct 8, 2024 08:45:43.938096046 CEST49674443192.168.2.523.1.237.91
Oct 8, 2024 08:45:44.030462027 CEST49673443192.168.2.523.1.237.91
Oct 8, 2024 08:45:44.349037886 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:44.349502087 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:44.349522114 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:44.351146936 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:44.351797104 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:44.354083061 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:44.354168892 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:44.405538082 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:44.405567884 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:44.452436924 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:45.689367056 CEST4434970323.1.237.91192.168.2.5
Oct 8, 2024 08:45:45.689666986 CEST49703443192.168.2.523.1.237.91
Oct 8, 2024 08:45:54.258402109 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:54.258471966 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:54.258526087 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:55.409825087 CEST49711443192.168.2.5172.217.16.196
Oct 8, 2024 08:45:55.409854889 CEST44349711172.217.16.196192.168.2.5
Oct 8, 2024 08:45:56.142682076 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.142777920 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.142965078 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.143225908 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.143255949 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.846236944 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.846483946 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.848836899 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.848869085 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.849282026 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.855462074 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.899419069 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.967772961 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.967834949 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.967876911 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.968054056 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.968055010 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:56.968126059 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:56.968348980 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.055526972 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.055587053 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.055763960 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.055763960 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.055830956 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.055953026 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.056860924 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.056911945 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.056962013 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.056976080 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.057017088 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.057099104 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.147438049 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.147515059 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.147706032 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.147706032 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.147778988 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.147972107 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.148802042 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.148849010 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.148914099 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.148921967 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.148952961 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.149070978 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.150722980 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.150770903 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.150815010 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.150821924 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.150854111 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.150985003 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.151648045 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.151700020 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.151748896 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.151756048 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.151787996 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.151926041 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.239866972 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.239927053 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.239979982 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.239990950 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.240021944 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.240154028 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.240456104 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.240504980 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.240549088 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.240555048 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.240601063 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.240608931 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.241077900 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.241126060 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.241168022 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.241173029 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.241200924 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.241354942 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.242036104 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242075920 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242120028 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.242125988 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242156982 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.242240906 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.242865086 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242907047 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242950916 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.242957115 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.242995977 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.243107080 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.243695974 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.243740082 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.243782997 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.243798018 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.243829012 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.243923903 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.244463921 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.244599104 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.244599104 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.244611979 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.244651079 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.244659901 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.244674921 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.244748116 CEST49719443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.244752884 CEST4434971913.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.282187939 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.282249928 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.282298088 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.282327890 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.282366991 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.282494068 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.282629967 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.282649994 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.283685923 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.283699036 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.285537958 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285537958 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285573006 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.285583019 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.285603046 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285624027 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.285655975 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285655975 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285789967 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285799980 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.285826921 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285835028 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.285844088 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.286145926 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.286161900 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.918569088 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.918975115 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.919028044 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.920310974 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.920325041 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.923177958 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.923475981 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.923500061 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.923778057 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.923782110 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.924046040 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.924304008 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.924313068 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.924658060 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.924663067 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.952708006 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.953030109 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.953042984 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:57.953355074 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:57.953358889 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.020946026 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.021018028 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.021085024 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.021184921 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.021222115 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.021250010 CEST49723443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.021265030 CEST4434972313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.022671938 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.022818089 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.022893906 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.022947073 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.022978067 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023019075 CEST49725443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023040056 CEST4434972513.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023241043 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023294926 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023407936 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023421049 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023441076 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023459911 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023463011 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023511887 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023560047 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023663044 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023663044 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023674965 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023685932 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.023715973 CEST49724443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.023720026 CEST4434972413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.025242090 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025286913 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.025377035 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025537014 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025538921 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025568962 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.025573969 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.025624990 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025755882 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.025772095 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055648088 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055695057 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055754900 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.055788994 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055820942 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055877924 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.055917978 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.055918932 CEST49726443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.055944920 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.055965900 CEST4434972613.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.057893038 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.057934999 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.057993889 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.058125973 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.058141947 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.665858984 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.666263103 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.666323900 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.666784048 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.666799068 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.671034098 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.671336889 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.671375990 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.671746016 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.671755075 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.694554090 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.694940090 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.694952011 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.695200920 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.695210934 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.726622105 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.730385065 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.730406046 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.730757952 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.730765104 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.765747070 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.765919924 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.766119957 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.767265081 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.767265081 CEST49728443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.767303944 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.767381907 CEST4434972813.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.771573067 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.771734953 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.772116899 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.776340961 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.776340961 CEST49729443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.776364088 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.776376009 CEST4434972913.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.778913975 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.778923988 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.778949976 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.778973103 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.779058933 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.779105902 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.779159069 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.779170036 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.779325962 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.779356956 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.795783997 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.795852900 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.796037912 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.799906969 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.799906969 CEST49727443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.799921036 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.799928904 CEST4434972713.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.806116104 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.806202888 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.806415081 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.806415081 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.806498051 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.829843998 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.829911947 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.832546949 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.832590103 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.832590103 CEST49730443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.832611084 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.832627058 CEST4434973013.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.834217072 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.834242105 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:58.834342957 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.836405993 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:58.836436987 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.420862913 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.420922995 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.421658993 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.421658993 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.421672106 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.421685934 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.421915054 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.421967983 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.422224998 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.422240019 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.471199036 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.471693039 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.471714020 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.471982002 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.472037077 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.501173019 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.501802921 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.501802921 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.501866102 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.501915932 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.520733118 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.520886898 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.521039009 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.521039963 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.521089077 CEST49731443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.521116972 CEST4434973113.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.522377968 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.522533894 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.522692919 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.522692919 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.522692919 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.523672104 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.523710012 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.524132967 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.524315119 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.524338007 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.524812937 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.524857998 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.525028944 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.525028944 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.525068045 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.575042009 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.575114012 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.575238943 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.575381041 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.575400114 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.575429916 CEST49733443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.575436115 CEST4434973313.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.577171087 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.577203989 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.577394962 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.577394962 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.577428102 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.605680943 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.605751038 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.606062889 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.606184006 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.606204033 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.606375933 CEST49734443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.606386900 CEST4434973413.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.607986927 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.608000994 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.608093023 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.608227015 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.608244896 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:45:59.826911926 CEST49732443192.168.2.513.107.246.60
Oct 8, 2024 08:45:59.826939106 CEST4434973213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.192872047 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.193342924 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.193365097 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.193757057 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.193761110 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.194500923 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.194834948 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.194844961 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.195409060 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.195414066 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.220186949 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.220525026 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.220566988 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.220613956 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.221203089 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.221210003 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.221496105 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.221513033 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.222023010 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.222033978 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.249010086 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.249299049 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.249315977 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.249618053 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.249624014 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.296942949 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.297111034 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.297261953 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.297383070 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.297383070 CEST49735443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.297395945 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.297411919 CEST4434973513.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.299750090 CEST49739443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.299786091 CEST4434973913.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.299854040 CEST49739443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.299969912 CEST49739443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.299978018 CEST4434973913.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.314069033 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.314218044 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.314349890 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.314423084 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.314424038 CEST49736443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.314445972 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.314455986 CEST4434973613.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.316545010 CEST49740443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.316618919 CEST4434974013.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.316699028 CEST49740443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.316790104 CEST49740443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.316807032 CEST4434974013.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.320599079 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.320688009 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.320784092 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.320914984 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.320930004 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.320941925 CEST49737443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.320947886 CEST4434973713.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.322653055 CEST49741443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.322747946 CEST4434974113.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.322825909 CEST49741443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.322942019 CEST49741443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.322981119 CEST4434974113.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327194929 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327214956 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327272892 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.327296019 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327347994 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.327354908 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327372074 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327447891 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.327466965 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327476978 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.327476978 CEST49722443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.327483892 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.327488899 CEST4434972213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.329493046 CEST49742443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.329516888 CEST4434974213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.329586029 CEST49742443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.329679012 CEST49742443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.329705954 CEST4434974213.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.347764015 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.347918034 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.348036051 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.348063946 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.348072052 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.348083019 CEST49738443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.348088026 CEST4434973813.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.349911928 CEST49743443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.349996090 CEST4434974313.107.246.60192.168.2.5
Oct 8, 2024 08:46:00.350092888 CEST49743443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.350272894 CEST49743443192.168.2.513.107.246.60
Oct 8, 2024 08:46:00.350292921 CEST4434974313.107.246.60192.168.2.5
TimestampSource PortDest PortSource IPDest IP
Oct 8, 2024 08:45:39.221884966 CEST53636931.1.1.1192.168.2.5
Oct 8, 2024 08:45:39.222485065 CEST53552631.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.238590002 CEST53639361.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.713737965 CEST6467553192.168.2.51.1.1.1
Oct 8, 2024 08:45:40.713979006 CEST5256853192.168.2.51.1.1.1
Oct 8, 2024 08:45:40.755212069 CEST53525681.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.757982016 CEST53646751.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.758644104 CEST6229253192.168.2.51.1.1.1
Oct 8, 2024 08:45:40.801963091 CEST53622921.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.822451115 CEST6456153192.168.2.58.8.8.8
Oct 8, 2024 08:45:40.822921991 CEST5264553192.168.2.51.1.1.1
Oct 8, 2024 08:45:40.829657078 CEST53526451.1.1.1192.168.2.5
Oct 8, 2024 08:45:40.831451893 CEST53645618.8.8.8192.168.2.5
Oct 8, 2024 08:45:41.829891920 CEST5304053192.168.2.51.1.1.1
Oct 8, 2024 08:45:41.830092907 CEST5568653192.168.2.51.1.1.1
Oct 8, 2024 08:45:41.837230921 CEST53556861.1.1.1192.168.2.5
Oct 8, 2024 08:45:41.873769999 CEST53530401.1.1.1192.168.2.5
Oct 8, 2024 08:45:43.669863939 CEST5918053192.168.2.51.1.1.1
Oct 8, 2024 08:45:43.669863939 CEST6016653192.168.2.51.1.1.1
Oct 8, 2024 08:45:43.676482916 CEST53601661.1.1.1192.168.2.5
Oct 8, 2024 08:45:43.676501036 CEST53591801.1.1.1192.168.2.5
Oct 8, 2024 08:45:46.900804043 CEST6328153192.168.2.51.1.1.1
Oct 8, 2024 08:45:46.901212931 CEST5116553192.168.2.51.1.1.1
Oct 8, 2024 08:45:46.942606926 CEST53632811.1.1.1192.168.2.5
Oct 8, 2024 08:45:46.945292950 CEST53511651.1.1.1192.168.2.5
Oct 8, 2024 08:45:46.945791006 CEST6274653192.168.2.51.1.1.1
Oct 8, 2024 08:45:46.990012884 CEST53627461.1.1.1192.168.2.5
Oct 8, 2024 08:45:57.366322994 CEST53550841.1.1.1192.168.2.5
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Oct 8, 2024 08:45:40.713737965 CEST192.168.2.51.1.1.10x96b8Standard query (0)aeat.esA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:40.713979006 CEST192.168.2.51.1.1.10x2200Standard query (0)aeat.es65IN (0x0001)false
Oct 8, 2024 08:45:40.758644104 CEST192.168.2.51.1.1.10x2dbStandard query (0)aeat.esA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:40.822451115 CEST192.168.2.58.8.8.80x5a5Standard query (0)google.comA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:40.822921991 CEST192.168.2.51.1.1.10x8817Standard query (0)google.comA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:41.829891920 CEST192.168.2.51.1.1.10xd3daStandard query (0)aeat.esA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:41.830092907 CEST192.168.2.51.1.1.10x2b09Standard query (0)aeat.es65IN (0x0001)false
Oct 8, 2024 08:45:43.669863939 CEST192.168.2.51.1.1.10xd424Standard query (0)www.google.comA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:43.669863939 CEST192.168.2.51.1.1.10x663bStandard query (0)www.google.com65IN (0x0001)false
Oct 8, 2024 08:45:46.900804043 CEST192.168.2.51.1.1.10x8109Standard query (0)aeat.esA (IP address)IN (0x0001)false
Oct 8, 2024 08:45:46.901212931 CEST192.168.2.51.1.1.10x2740Standard query (0)aeat.es65IN (0x0001)false
Oct 8, 2024 08:45:46.945791006 CEST192.168.2.51.1.1.10x653eStandard query (0)aeat.esA (IP address)IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Oct 8, 2024 08:45:40.829657078 CEST1.1.1.1192.168.2.50x8817No error (0)google.com172.217.16.206A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:40.831451893 CEST8.8.8.8192.168.2.50x5a5No error (0)google.com142.250.186.46A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:43.676482916 CEST1.1.1.1192.168.2.50x663bNo error (0)www.google.com65IN (0x0001)false
Oct 8, 2024 08:45:43.676501036 CEST1.1.1.1192.168.2.50xd424No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:54.994652033 CEST1.1.1.1192.168.2.50xb6afNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:54.994652033 CEST1.1.1.1192.168.2.50xb6afNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:55.489702940 CEST1.1.1.1192.168.2.50xb883No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
Oct 8, 2024 08:45:55.489702940 CEST1.1.1.1192.168.2.50xb883No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
Oct 8, 2024 08:45:56.141922951 CEST1.1.1.1192.168.2.50x5ac1No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.nets-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
Oct 8, 2024 08:45:56.141922951 CEST1.1.1.1192.168.2.50x5ac1No error (0)s-part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
  • otelrules.azureedge.net
Session IDSource IPSource PortDestination IPDestination Port
0192.168.2.54971913.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:56 UTC195OUTGET /rules/other-Win32-v19.bundle HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:56 UTC540INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:56 GMT
Content-Type: text/plain
Content-Length: 218853
Connection: close
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Cache-Control: public
Last-Modified: Sun, 06 Oct 2024 16:59:23 GMT
ETag: "0x8DCE6283A3FA58B"
x-ms-request-id: 86eceaf5-401e-00a3-6fa2-188b09000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064556Z-1657d5bbd48wd55zet5pcra0cg00000004ng000000002zwp
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:56 UTC15844INData Raw: 31 30 30 30 76 35 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 22 20 56 3d 22 35 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 52 75 6c 65 45 72 72 6f 72 73 41 67 67 72 65 67 61 74 65 64 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 53 3d 22 37 30 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20
Data Ascii: 1000v5+<?xml version="1.0" encoding="utf-8"?><R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU"
2024-10-08 06:45:57 UTC16384INData Raw: 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 42 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e
Data Ascii: "0" /> </L> <R> <V V="400" T="I32" /> </R> </O> </R> </O> </C> <C T="B" I="5" O="false"> <O T="AND"> <L> <O T="GE"> <L> <S T="1" F="0" />
2024-10-08 06:45:57 UTC16384INData Raw: 20 20 3c 53 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 53 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 38 32 30 76 33 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 38 32 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 6f 6e 74 61 63 74 43 61 72 64 50 72 6f 70 65 72 74 69 65 73 43 6f 75 6e 74 73 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31
Data Ascii: <ST> <S T="1" /> </ST></R><$!#>10820v3+<?xml version="1.0" encoding="utf-8"?><R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-781
2024-10-08 06:45:57 UTC16384INData Raw: 20 54 3d 22 55 36 34 22 20 49 3d 22 38 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 45 76 65 6e 74 73 5f 41 76 67 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 41 76 65 72 61 67 65 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 39 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 41 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20
Data Ascii: T="U64" I="8" O="false" N="Events_Avg"> <S T="2" F="Average" /> </C> <C T="U32" I="9" O="true" N="Purged_Age"> <S T="4" F="Count" /> </C> <C T="U32" I="10" O="true" N="Purged_Count"> <S T="5" F="Count" /> </C> <C T="U32"
2024-10-08 06:45:57 UTC16384INData Raw: 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 50 65 72 73 6f 6e 61 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 4d 61 6e 61 67 65 72 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f
Data Ascii: "0" O="false" N="Count_CreateCard_ValidPersona_False"> <C> <S T="10" /> </C> </C> <C T="U32" I="1" O="false" N="Count_CreateCard_ValidManager_False"> <C> <S T="11" /> </C> </C> <C T="U32" I="2" O="false" N="Co
2024-10-08 06:45:57 UTC16384INData Raw: 20 20 20 20 3c 53 20 54 3d 22 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 39 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 57 61 73 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a
Data Ascii: <S T="31" /> </C> </C> <C T="U32" I="19" O="false" N="Paint_IMsoPersona_WasNull_Count"> <C> <S T="32" /> </C> </C> <C T="U32" I="20" O="false" N="Paint_IMsoPersona_Null_Count"> <C> <S T="33" /> </C>
2024-10-08 06:45:57 UTC16384INData Raw: 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63 6f 6e 64 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 30 30 22 20 54 3d 22 49 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63
Data Ascii: <S T="3" F="RetrievalMilliseconds" /> </L> <R> <V V="200" T="I64" /> </R> </O> </L> <R> <O T="LT"> <L> <S T="3" F="RetrievalMillisec
2024-10-08 06:45:57 UTC16384INData Raw: 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 53 75 63 63 65 73 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e
Data Ascii: R> <V V="0" T="I32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount"> <C> <S T="9" /> </C> </C> <C T="U32" I="1" O="false" N="Ocom2IUCOfficeIn
2024-10-08 06:45:57 UTC16384INData Raw: 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 54 65 6e 61 6e 74 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 55 73 65 72 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20
Data Ascii: R> </O> </F> <F T="6"> <O T="AND"> <L> <S T="3" F="Tenant enabled" /> </L> <R> <O T="EQ"> <L> <S T="3" F="User enabled" /> </L>
2024-10-08 06:45:57 UTC16384INData Raw: 54 3d 22 36 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 48 74 74 70 53 74 61 74 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 34 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
Data Ascii: T="6"> <O T="EQ"> <L> <S T="2" F="HttpStatus" /> </L> <R> <V V="404" T="U32" /> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T="GE"> <


Session IDSource IPSource PortDestination IPDestination Port
1192.168.2.54972313.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:57 UTC192OUTGET /rules/rule224902v2s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:57 GMT
Content-Type: text/xml
Content-Length: 450
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:27:25 GMT
ETag: "0x8DC582BD4C869AE"
x-ms-request-id: d4448e94-101e-00a2-2703-179f2e000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064557Z-1657d5bbd487nf59mzf5b3gk8n0000000470000000008tzm
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC450INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 62 72 35 71 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 61 33 36 61 39 37 30 64 2d 34 35 61 39 2d 34 65 30 64 2d 39 63 61 62 2d 32 61 32 33 35 63 63 39 64 37 63 36 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 47 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 4e
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224902" V="2" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120100" /> <UTS T="2" Id="bbr5q" /> <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" /> </S> <C T="G" I="0" O="falseN


Session IDSource IPSource PortDestination IPDestination Port
2192.168.2.54972513.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:57 UTC192OUTGET /rules/rule120609v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:57 GMT
Content-Type: text/xml
Content-Length: 408
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
ETag: "0x8DC582BB56D3AFB"
x-ms-request-id: a57a937a-601e-003d-20e7-186f25000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064557Z-1657d5bbd48wd55zet5pcra0cg00000004mg0000000050wv
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 44 64 5d 5b 45 65 5d 5b 4c 6c 5d 5b 4c 6c 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120609" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120682" /> <SR T="2" R="^([Dd][Ee][Ll][Ll])"> <S T="1" F="0" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


Session IDSource IPSource PortDestination IPDestination Port
3192.168.2.54972413.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:57 UTC192OUTGET /rules/rule120600v4s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC563INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:57 GMT
Content-Type: text/xml
Content-Length: 2980
Connection: close
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
ETag: "0x8DC582BA80D96A1"
x-ms-request-id: 8aaf7b13-d01e-0028-46fd-167896000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064557Z-1657d5bbd482lxwq1dp2t1zwkc00000004b00000000085g6
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC2980INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 30 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 44 65 76 69 63 65 43 6f 6e 73 6f 6c 69 64 61 74 65 64 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC"


Session IDSource IPSource PortDestination IPDestination Port
4192.168.2.54972613.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:57 UTC192OUTGET /rules/rule120608v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC563INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:57 GMT
Content-Type: text/xml
Content-Length: 2160
Connection: close
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
ETag: "0x8DC582BA3B95D81"
x-ms-request-id: c59bb0f9-701e-0097-2d01-17b8c1000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064557Z-1657d5bbd4824mj9d6vp65b6n400000004sg000000009nw1
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC2160INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 37 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 33 22 20 52 3d 22 31 32 30 36 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 36 31 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 35 22 20 52 3d 22 31 32 30 36 31 34 22 20 2f 3e 0d 0a 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120609" /> <R T="2" R="120679" /> <R T="3" R="120610" /> <R T="4" R="120612" /> <R T="5" R="120614" />


Session IDSource IPSource PortDestination IPDestination Port
5192.168.2.54972813.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:58 UTC192OUTGET /rules/rule120611v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC491INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:58 GMT
Content-Type: text/xml
Content-Length: 415
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:56 GMT
ETag: "0x8DC582B9F6F3512"
x-ms-request-id: b6ff579e-d01e-0028-17ff-187896000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064558Z-1657d5bbd48xjgsr3pyv9u71rc00000000h00000000046s2
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
X-Cache-Info: L1_T2
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4c 6c 5d 5b 45 65 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 56 76 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120611" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


Session IDSource IPSource PortDestination IPDestination Port
6192.168.2.54972913.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:58 UTC192OUTGET /rules/rule120612v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:58 GMT
Content-Type: text/xml
Content-Length: 471
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:25 GMT
ETag: "0x8DC582BB10C598B"
x-ms-request-id: 73fc0cc0-d01e-008e-5fee-16387a000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064558Z-1657d5bbd4824mj9d6vp65b6n400000004qg00000000eee1
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120612" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
7192.168.2.54972713.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:58 UTC192OUTGET /rules/rule120610v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:58 GMT
Content-Type: text/xml
Content-Length: 474
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
ETag: "0x8DC582B9964B277"
x-ms-request-id: 3ea0840d-701e-0053-1012-173a0a000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064558Z-1657d5bbd48cpbzgkvtewk0wu000000004m000000000dhd8
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120610" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
8192.168.2.54973013.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:58 UTC192OUTGET /rules/rule120613v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:58 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:58 GMT
Content-Type: text/xml
Content-Length: 632
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
ETag: "0x8DC582BB6E3779E"
x-ms-request-id: 7e689a47-601e-0002-7978-18a786000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064558Z-1657d5bbd48hzllksrq1r6zsvs00000001x0000000002d87
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:58 UTC632INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 48 68 5d 5b 50 70 5d 28 5b 5e 45 5d 7c 24 29 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 33 22 20 52 3d 22 28 5b 48 68 5d 5b 45 65 5d 5b 57 77 5d 5b 4c 6c 5d 5b 45 65 5d
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120613" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <SR T="2" R="^([Hh][Pp]([^E]|$))"> <S T="1" F="1" M="Ignore" /> </SR> <SR T="3" R="([Hh][Ee][Ww][Ll][Ee]


Session IDSource IPSource PortDestination IPDestination Port
9192.168.2.54973213.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:59 UTC192OUTGET /rules/rule120615v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:59 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:59 GMT
Content-Type: text/xml
Content-Length: 407
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
ETag: "0x8DC582BBAD04B7B"
x-ms-request-id: 789c8418-601e-0032-5905-17eebb000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064559Z-1657d5bbd48t66tjar5xuq22r800000004kg0000000072fp
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:59 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 53 73 5d 5b 55 75 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120615" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <SR T="2" R="([Aa][Ss][Uu][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


Session IDSource IPSource PortDestination IPDestination Port
10192.168.2.54973113.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:59 UTC192OUTGET /rules/rule120614v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:59 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:59 GMT
Content-Type: text/xml
Content-Length: 467
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
ETag: "0x8DC582BA6C038BC"
x-ms-request-id: 0af727ec-a01e-000d-01e8-18d1ea000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064559Z-1657d5bbd482tlqpvyz9e93p5400000004r0000000004ztu
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:59 UTC467INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120614" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
11192.168.2.54973313.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:59 UTC192OUTGET /rules/rule120616v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:59 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:59 GMT
Content-Type: text/xml
Content-Length: 486
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
ETag: "0x8DC582BB344914B"
x-ms-request-id: 0a3893d3-c01e-0082-33ee-16af72000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064559Z-1657d5bbd48jwrqbupe3ktsx9w00000004s000000000azwp
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:59 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120616" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
12192.168.2.54973413.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:45:59 UTC192OUTGET /rules/rule120617v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:45:59 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:45:59 GMT
Content-Type: text/xml
Content-Length: 427
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:02 GMT
ETag: "0x8DC582BA310DA18"
x-ms-request-id: 915c1ee4-001e-0079-3000-1712e8000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064559Z-1657d5bbd48sdh4cyzadbb374800000004gg000000003d0f
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:45:59 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120617" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


Session IDSource IPSource PortDestination IPDestination Port
13192.168.2.54973613.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120619v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:00 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 407
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:41 GMT
ETag: "0x8DC582B9698189B"
x-ms-request-id: 99ffd5e0-b01e-0053-0101-17cdf8000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48tnj6wmberkg2xy800000004tg000000000ufx
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:00 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 43 63 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120619" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <SR T="2" R="([Aa][Cc][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


Session IDSource IPSource PortDestination IPDestination Port
14192.168.2.54973513.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120618v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:00 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 486
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:30 GMT
ETag: "0x8DC582B9018290B"
x-ms-request-id: 2bf76a5c-f01e-0096-08eb-1810ef000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48xjgsr3pyv9u71rc00000000g0000000004fqt
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:00 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120618" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
15192.168.2.54973713.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120620v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:00 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 469
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
ETag: "0x8DC582BBA701121"
x-ms-request-id: e72ec3ca-501e-005b-2401-17d7f7000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48gqrfwecymhhbfm800000003f00000000052vw
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:00 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120620" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
16192.168.2.54972213.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC193OUTGET /rules/rule120402v21s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:00 UTC563INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 3788
Connection: close
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
ETag: "0x8DC582BAC2126A6"
x-ms-request-id: 4545068c-701e-0050-0e05-176767000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48vlsxxpe15ac3q7n00000004q0000000001kx4
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:00 UTC3788INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 34 30 32 22 20 56 3d 22 32 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 6e 67 72 61 63 65 66 75 6c 41 70 70 45 78 69 74 44 65 73 6b 74 6f 70 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 22 20 78 6d 6c 6e 73 3d 22 22
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns=""


Session IDSource IPSource PortDestination IPDestination Port
17192.168.2.54973813.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120621v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:00 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 415
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
ETag: "0x8DC582BA41997E3"
x-ms-request-id: 27ba9a72-001e-0046-2a01-17da4b000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48sqtlf1huhzuwq70000000047000000000gfw8
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:00 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 56 76 5d 5b 4d 6d 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120621" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


Session IDSource IPSource PortDestination IPDestination Port
18192.168.2.54974013.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120623v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 464
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
ETag: "0x8DC582B97FB6C3C"
x-ms-request-id: ca51ad8b-f01e-0085-6ef2-1888ea000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd482lxwq1dp2t1zwkc00000004bg0000000070kp
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC464INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 49 69 5d 5b 47 67 5d 5b 41 61 5d 5b 42 62 5d 5b 59 79 5d 5b 54 74 5d 5b 45 65 5d 20 5b 54 74 5d 5b 45 65 5d 5b 43 63 5d 5b 48 68 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 47 67 5d 5b 59 79 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120623" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])"> <S T="1" F="1" M="Ignor


Session IDSource IPSource PortDestination IPDestination Port
19192.168.2.54973913.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120622v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 477
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
ETag: "0x8DC582BB8CEAC16"
x-ms-request-id: c2d0a885-201e-0003-7ced-16f85a000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd482krtfgrg72dfbtn00000004eg000000001mmu
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120622" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
20192.168.2.54974213.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120625v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:00 GMT
Content-Type: text/xml
Content-Length: 419
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:42 GMT
ETag: "0x8DC582B9748630E"
x-ms-request-id: 09392ef7-101e-0046-3f05-1791b0000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064600Z-1657d5bbd48lknvp09v995n790000000044000000000fc90
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 46 66 5d 5b 55 75 5d 5b 4a 6a 5d 5b 49 69 5d 5b 54 74 5d 5b 53 73 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120625" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


Session IDSource IPSource PortDestination IPDestination Port
21192.168.2.54974113.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:00 UTC192OUTGET /rules/rule120624v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 494
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
ETag: "0x8DC582BB7010D66"
x-ms-request-id: d3d0b776-b01e-003d-1803-17d32c000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48wd55zet5pcra0cg00000004k0000000007bxh
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120624" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
22192.168.2.54974313.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120626v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 472
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
ETag: "0x8DC582B9DACDF62"
x-ms-request-id: 20b36261-201e-006e-7102-17bbe3000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48xlwdx82gahegw4000000004qg00000000dg7e
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120626" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
23192.168.2.54974513.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120628v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 468
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
ETag: "0x8DC582B9C8E04C8"
x-ms-request-id: d112c6a6-a01e-000d-2160-17d1ea000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48lknvp09v995n790000000044000000000fc9n
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120628" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
24192.168.2.54974613.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120629v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 428
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
ETag: "0x8DC582BAC4F34CA"
x-ms-request-id: 6be05283-001e-00a2-2700-17d4d5000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd482tlqpvyz9e93p5400000004kg00000000dxst
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC428INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 2d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120629" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


Session IDSource IPSource PortDestination IPDestination Port
25192.168.2.54974413.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120627v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 404
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:54 GMT
ETag: "0x8DC582B9E8EE0F3"
x-ms-request-id: f57b7c9f-801e-00a0-4a13-172196000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48tnj6wmberkg2xy800000004kg00000000dxx0
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4e 6e 5d 5b 45 65 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120627" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <SR T="2" R="^([Nn][Ee][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


Session IDSource IPSource PortDestination IPDestination Port
26192.168.2.54974813.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120631v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 415
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
ETag: "0x8DC582B988EBD12"
x-ms-request-id: c530354f-501e-0016-5013-17181b000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48dfrdj7px744zp8s00000004bg000000005pwz
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 48 68 5d 5b 55 75 5d 5b 41 61 5d 5b 57 77 5d 5b 45 65 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120631" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


Session IDSource IPSource PortDestination IPDestination Port
27192.168.2.54974713.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:01 UTC192OUTGET /rules/rule120630v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:01 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:01 GMT
Content-Type: text/xml
Content-Length: 499
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:25:45 GMT
ETag: "0x8DC582B98CEC9F6"
x-ms-request-id: 40323690-a01e-0002-0100-175074000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064601Z-1657d5bbd48lknvp09v995n79000000004900000000048ya
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:01 UTC499INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120630" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
28192.168.2.54975113.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:02 UTC192OUTGET /rules/rule120634v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:02 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:02 GMT
Content-Type: text/xml
Content-Length: 494
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
ETag: "0x8DC582BB8972972"
x-ms-request-id: 7c825ef0-601e-0001-5f02-17faeb000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064602Z-1657d5bbd48qjg85buwfdynm5w00000004kg00000000fews
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:02 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120634" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
29192.168.2.54975013.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:02 UTC192OUTGET /rules/rule120633v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:02 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:02 GMT
Content-Type: text/xml
Content-Length: 419
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
ETag: "0x8DC582BB32BB5CB"
x-ms-request-id: d415a278-e01e-0051-6efe-1684b2000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064602Z-1657d5bbd48gqrfwecymhhbfm800000003hg000000000zdy
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:02 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 53 73 5d 5b 41 61 5d 5b 4d 6d 5d 5b 53 73 5d 5b 55 75 5d 5b 4e 6e 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120633" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


Session IDSource IPSource PortDestination IPDestination Port
30192.168.2.54974913.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:02 UTC192OUTGET /rules/rule120632v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net
2024-10-08 06:46:02 UTC470INHTTP/1.1 200 OK
Date: Tue, 08 Oct 2024 06:46:02 GMT
Content-Type: text/xml
Content-Length: 471
Connection: close
Cache-Control: public, max-age=604800, immutable
Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
ETag: "0x8DC582BB5815C4C"
x-ms-request-id: 490a0185-101e-0046-80ac-1891b0000000
x-ms-version: 2018-03-28
x-azure-ref: 20241008T064602Z-1657d5bbd48hzllksrq1r6zsvs00000001wg0000000033gv
x-fd-int-roxy-purgeid: 0
X-Cache: TCP_HIT
Accept-Ranges: bytes
2024-10-08 06:46:02 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120632" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


Session IDSource IPSource PortDestination IPDestination Port
31192.168.2.54975213.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:02 UTC192OUTGET /rules/rule120635v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net


Session IDSource IPSource PortDestination IPDestination Port
32192.168.2.54975313.107.246.60443
TimestampBytes transferredDirectionData
2024-10-08 06:46:02 UTC192OUTGET /rules/rule120636v0s19.xml HTTP/1.1
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
Host: otelrules.azureedge.net


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:02:45:36
Start date:08/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:02:45:37
Start date:08/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1972,i,4360780461697686295,14656468667491634171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:3
Start time:02:45:39
Start date:08/10/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aeat.es"
Imagebase:0x7ff715980000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly