Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://downloads.slack-edge.com

Overview

General Information

Sample URL:http://downloads.slack-edge.com
Analysis ID:1530964
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5628 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2288,i,8993466432769708361,9923647099172993640,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6296 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://downloads.slack-edge.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.203.209
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: downloads.slack-edge.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://downloads.slack-edge.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: downloads.slack-edge.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: downloads.slack-edge.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closex-amz-bucket-region: us-west-2Date: Thu, 10 Oct 2024 16:21:17 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 111f802abddccd55d219ff1635e1aa4a.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA56-P11X-Amz-Cf-Id: WTsSoUpSAA2YuGIm_gHX11v6pml1PuVu3crUZiZeerD35Rwjizdgow==
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeDate: Thu, 10 Oct 2024 16:21:20 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 d025091c574ce1bcf1fefea59ac34f2c.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA56-P11X-Amz-Cf-Id: QuzHluV59vmBg9MJH3nc6ro8I7eUc4UCMRHUMU9ul4qWQ-rNpG970w==
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: classification engineClassification label: unknown0.win@22/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2288,i,8993466432769708361,9923647099172993640,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://downloads.slack-edge.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2288,i,8993466432769708361,9923647099172993640,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.185.164
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        d25f4v0ddt3j8p.cloudfront.net
        18.244.18.103
        truefalse
          unknown
          downloads.slack-edge.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://downloads.slack-edge.com/false
              unknown
              http://downloads.slack-edge.com/false
                unknown
                https://downloads.slack-edge.com/favicon.icofalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.185.164
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  18.244.18.20
                  unknownUnited States
                  16509AMAZON-02USfalse
                  18.244.18.103
                  d25f4v0ddt3j8p.cloudfront.netUnited States
                  16509AMAZON-02USfalse
                  IP
                  192.168.2.4
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1530964
                  Start date and time:2024-10-10 18:20:14 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 1m 57s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://downloads.slack-edge.com
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:UNKNOWN
                  Classification:unknown0.win@22/4@6/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • URL browsing timeout or error
                  • URL not reachable
                  • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.186.78, 64.233.166.84, 142.250.184.195, 34.104.35.123, 172.202.163.200, 199.232.210.172, 192.229.221.95, 20.242.39.171
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: http://downloads.slack-edge.com
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:XML 1.0 document, ASCII text
                  Category:downloaded
                  Size (bytes):243
                  Entropy (8bit):5.4871149194045055
                  Encrypted:false
                  SSDEEP:6:TMVBd/ZbZjZvKtWRVzjNiuURrMBf3cMEqyDjUan:TMHd9BZKtWRHNU9If30Ia
                  MD5:7E34530BE2207C22F1CEE1E875EDF1D5
                  SHA1:68EE3554D85848FD41121BE124A9E8246F8DBBEE
                  SHA-256:9D16A7BBE87AA4E1675496BA79740CAFFC04440CE73167840BE7D9741A8B8020
                  SHA-512:2E2F8A49AD7983A421D2F5307861C654953FED4CA4120DDCCF6C3652D9D9FCB0EAEAB0404121EE3D9D54DBDCB4E210C4A067AB5583908022631A5E97D745942A
                  Malicious:false
                  Reputation:low
                  URL:https://downloads.slack-edge.com/
                  Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>VCDZNSYEVTGKKFSD</RequestId><HostId>QSap9L1EcJrUHKUMCC1VAecKpvt1lMYeo1U/ZgYNE2N4UGtAfnNVu46L93WbPDTDLQFEcGedeXM=</HostId></Error>
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:XML 1.0 document, ASCII text
                  Category:downloaded
                  Size (bytes):243
                  Entropy (8bit):5.517282441201655
                  Encrypted:false
                  SSDEEP:6:TMVBd/ZbZjZvKtWRVzjktkUCBP9nEh7FrarNVeMfzUan:TMHd9BZKtWRJyhBrafeMfYa
                  MD5:B97BB9A9C7DADB37DC8A84D7BAD1FA95
                  SHA1:E0488D8AA39FAD2D5163B7EA02002564108B0547
                  SHA-256:88EFBFCD6EB2D0387D416B77C300917C051147A6348EB08CAA92FC4D59B17309
                  SHA-512:BB99D244EDDA4853951DD1C312B961DC23579B72B0A81B604F4C6D2B55A4F54DE43B65AB942E7F439580095D3CAA368A1F6B0C336AA054BD6B68D019CC0D685D
                  Malicious:false
                  Reputation:low
                  URL:https://downloads.slack-edge.com/favicon.ico
                  Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>H3JW3H31XED51D8A</RequestId><HostId>uXgA6nEjuJFSGM9HxgtgdqDhLk1bVtNs3hSZPvqu1IO/HGmZrt9AzZCKutWYsjQcP2M1/Hqxcdk=</HostId></Error>
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 10, 2024 18:21:08.046092987 CEST49675443192.168.2.4173.222.162.32
                  Oct 10, 2024 18:21:09.142237902 CEST4974880192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.143328905 CEST4974980192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.147198915 CEST804974818.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:09.147274971 CEST4974880192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.147614956 CEST4974880192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.148435116 CEST804974918.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:09.148494959 CEST4974980192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.152806997 CEST804974818.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:09.152836084 CEST804974818.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:09.154227972 CEST804974918.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:09.154290915 CEST4974980192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.241506100 CEST4974980192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:09.246402025 CEST804974918.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.232037067 CEST4975380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.232208014 CEST4975480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.237677097 CEST804975318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.237695932 CEST804975418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.237763882 CEST4975380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.237793922 CEST4975480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.240453959 CEST4975380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.242997885 CEST804975318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.243062973 CEST4975380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.243135929 CEST804975418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.243175983 CEST4975380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.243275881 CEST4975480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.243275881 CEST4975480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.243527889 CEST4975580192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.245457888 CEST804975318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.247838974 CEST804975318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.247948885 CEST804975318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.248433113 CEST804975418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.248485088 CEST804975518.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.248553991 CEST4975580192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.248688936 CEST4975580192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:10.255347013 CEST804975518.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:10.255438089 CEST804975518.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:11.274727106 CEST49756443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.274750948 CEST44349756142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.274816036 CEST49756443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.275089025 CEST49756443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.275104046 CEST44349756142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.288233995 CEST44349756142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.288710117 CEST49757443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.288743019 CEST44349757142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.288857937 CEST49757443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.288991928 CEST49757443192.168.2.4142.250.185.164
                  Oct 10, 2024 18:21:11.289004087 CEST44349757142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.300982952 CEST44349757142.250.185.164192.168.2.4
                  Oct 10, 2024 18:21:11.996151924 CEST49758443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:11.996180058 CEST4434975823.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:11.996277094 CEST49758443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:11.997771025 CEST49758443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:11.997781992 CEST4434975823.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.009618044 CEST4434975823.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.009977102 CEST49759443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.010010958 CEST4434975923.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.010086060 CEST49759443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.010304928 CEST49759443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.010324955 CEST4434975923.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.021287918 CEST4434975923.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.021559954 CEST49760443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.021578074 CEST4434976023.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.021637917 CEST49760443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.022200108 CEST49760443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:12.022233009 CEST4434976023.60.203.209192.168.2.4
                  Oct 10, 2024 18:21:12.022283077 CEST49760443192.168.2.423.60.203.209
                  Oct 10, 2024 18:21:13.955447912 CEST4976180192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.955674887 CEST4976280192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.960508108 CEST804976118.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.960680962 CEST4976180192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.960689068 CEST804976218.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.960760117 CEST4976280192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.965361118 CEST4976180192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.966051102 CEST804976118.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.966119051 CEST4976180192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.966315985 CEST804976218.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.966460943 CEST4976180192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.966479063 CEST4976280192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.970333099 CEST804976118.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.971086979 CEST804976118.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.971462965 CEST804976118.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:13.981744051 CEST4976280192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:13.986670017 CEST804976218.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:14.999846935 CEST4976380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.000509024 CEST4976480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.006341934 CEST804976318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:15.006474018 CEST4976380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.006633043 CEST804976418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:15.006692886 CEST4976380192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.006695032 CEST4976480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.012271881 CEST804976318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:15.013561010 CEST804976318.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:15.017764091 CEST804976418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:15.017829895 CEST4976480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.039474964 CEST4976480192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:15.045325041 CEST804976418.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.042701006 CEST4976580192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:16.042795897 CEST4976680192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:16.047702074 CEST804976518.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.047780037 CEST4976580192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:16.048026085 CEST804976618.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.048090935 CEST4976680192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:16.058574915 CEST4976680192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:16.063621044 CEST804976618.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.993838072 CEST804976618.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.994976044 CEST804976618.244.18.103192.168.2.4
                  Oct 10, 2024 18:21:16.995022058 CEST4976680192.168.2.418.244.18.103
                  Oct 10, 2024 18:21:17.084881067 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.084922075 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.084988117 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.085304022 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.085318089 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.751038074 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.755199909 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.755214930 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.756108046 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.756170034 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.899024010 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.899197102 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.899209023 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.899230003 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:17.949655056 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:17.949683905 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:18.005644083 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.664128065 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:18.664433956 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:18.664544106 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.666320086 CEST49767443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.666337967 CEST4434976718.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:18.911226988 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.911251068 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:18.911372900 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.911631107 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:18.911647081 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:19.541476965 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:19.541759968 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:19.541791916 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:19.542138100 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:19.542548895 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:19.542615891 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:19.542722940 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:19.583406925 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:20.391906977 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:20.392213106 CEST4434976818.244.18.20192.168.2.4
                  Oct 10, 2024 18:21:20.392271996 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:20.567070961 CEST49768443192.168.2.418.244.18.20
                  Oct 10, 2024 18:21:20.567099094 CEST4434976818.244.18.20192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Oct 10, 2024 18:21:07.561800957 CEST53521211.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:07.563088894 CEST53562771.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:09.124170065 CEST5039853192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:09.124352932 CEST5112153192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:09.131530046 CEST53511211.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:09.141591072 CEST53503981.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:10.550668955 CEST53652591.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:11.266258955 CEST5048753192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:11.266415119 CEST5903253192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:11.273430109 CEST53590321.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:11.274019003 CEST53504871.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:16.999052048 CEST6511453192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:17.024117947 CEST5369953192.168.2.41.1.1.1
                  Oct 10, 2024 18:21:17.044395924 CEST53536991.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:17.084194899 CEST53651141.1.1.1192.168.2.4
                  Oct 10, 2024 18:21:27.210664988 CEST138138192.168.2.4192.168.2.255
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Oct 10, 2024 18:21:09.124170065 CEST192.168.2.41.1.1.10xd840Standard query (0)downloads.slack-edge.comA (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:09.124352932 CEST192.168.2.41.1.1.10xadaaStandard query (0)downloads.slack-edge.com65IN (0x0001)false
                  Oct 10, 2024 18:21:11.266258955 CEST192.168.2.41.1.1.10xe856Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:11.266415119 CEST192.168.2.41.1.1.10x2383Standard query (0)www.google.com65IN (0x0001)false
                  Oct 10, 2024 18:21:16.999052048 CEST192.168.2.41.1.1.10x7656Standard query (0)downloads.slack-edge.comA (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:17.024117947 CEST192.168.2.41.1.1.10x8b0dStandard query (0)downloads.slack-edge.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Oct 10, 2024 18:21:09.131530046 CEST1.1.1.1192.168.2.40xadaaNo error (0)downloads.slack-edge.comd25f4v0ddt3j8p.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                  Oct 10, 2024 18:21:09.141591072 CEST1.1.1.1192.168.2.40xd840No error (0)downloads.slack-edge.comd25f4v0ddt3j8p.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                  Oct 10, 2024 18:21:09.141591072 CEST1.1.1.1192.168.2.40xd840No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.103A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:09.141591072 CEST1.1.1.1192.168.2.40xd840No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.60A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:09.141591072 CEST1.1.1.1192.168.2.40xd840No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.20A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:09.141591072 CEST1.1.1.1192.168.2.40xd840No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.25A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:11.273430109 CEST1.1.1.1192.168.2.40x2383No error (0)www.google.com65IN (0x0001)false
                  Oct 10, 2024 18:21:11.274019003 CEST1.1.1.1192.168.2.40xe856No error (0)www.google.com142.250.185.164A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:17.044395924 CEST1.1.1.1192.168.2.40x8b0dNo error (0)downloads.slack-edge.comd25f4v0ddt3j8p.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                  Oct 10, 2024 18:21:17.084194899 CEST1.1.1.1192.168.2.40x7656No error (0)downloads.slack-edge.comd25f4v0ddt3j8p.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                  Oct 10, 2024 18:21:17.084194899 CEST1.1.1.1192.168.2.40x7656No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.20A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:17.084194899 CEST1.1.1.1192.168.2.40x7656No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.60A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:17.084194899 CEST1.1.1.1192.168.2.40x7656No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.25A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:17.084194899 CEST1.1.1.1192.168.2.40x7656No error (0)d25f4v0ddt3j8p.cloudfront.net18.244.18.103A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:21.959773064 CEST1.1.1.1192.168.2.40xf3eNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:21.959773064 CEST1.1.1.1192.168.2.40xf3eNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                  Oct 10, 2024 18:21:22.517654896 CEST1.1.1.1192.168.2.40x3cdcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Oct 10, 2024 18:21:22.517654896 CEST1.1.1.1192.168.2.40x3cdcNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                  • downloads.slack-edge.com
                  • https:
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44974818.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:09.147614956 CEST439OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44975318.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:10.240453959 CEST465OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.44975518.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:10.248688936 CEST465OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.44976118.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:13.965361118 CEST465OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.44976318.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:15.006692886 CEST465OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  5192.168.2.44976618.244.18.103803940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Oct 10, 2024 18:21:16.058574915 CEST465OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Oct 10, 2024 18:21:16.993838072 CEST575INHTTP/1.1 301 Moved Permanently
                  Server: CloudFront
                  Date: Thu, 10 Oct 2024 16:21:16 GMT
                  Content-Type: text/html
                  Content-Length: 167
                  Connection: keep-alive
                  Location: https://downloads.slack-edge.com/
                  X-Cache: Redirect from cloudfront
                  Via: 1.1 11c65b00bf7f76c861a15dcad5558b9c.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P11
                  X-Amz-Cf-Id: tHqy5B80o1hol705jcR47EcyY9jqgJollc6Gj1EDoezh92b7mvKvfg==
                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 43 6c 6f 75 64 46 72 6f 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>CloudFront</center></body></html>
                  Oct 10, 2024 18:21:16.994976044 CEST575INHTTP/1.1 301 Moved Permanently
                  Server: CloudFront
                  Date: Thu, 10 Oct 2024 16:21:16 GMT
                  Content-Type: text/html
                  Content-Length: 167
                  Connection: keep-alive
                  Location: https://downloads.slack-edge.com/
                  X-Cache: Redirect from cloudfront
                  Via: 1.1 11c65b00bf7f76c861a15dcad5558b9c.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P11
                  X-Amz-Cf-Id: tHqy5B80o1hol705jcR47EcyY9jqgJollc6Gj1EDoezh92b7mvKvfg==
                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 43 6c 6f 75 64 46 72 6f 6e 74 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>CloudFront</center></body></html>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44976718.244.18.204433940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-10 16:21:17 UTC679OUTGET / HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  Cache-Control: max-age=0
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: cross-site
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-10-10 16:21:18 UTC390INHTTP/1.1 403 Forbidden
                  Content-Type: application/xml
                  Transfer-Encoding: chunked
                  Connection: close
                  x-amz-bucket-region: us-west-2
                  Date: Thu, 10 Oct 2024 16:21:17 GMT
                  Server: AmazonS3
                  X-Cache: Error from cloudfront
                  Via: 1.1 111f802abddccd55d219ff1635e1aa4a.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P11
                  X-Amz-Cf-Id: WTsSoUpSAA2YuGIm_gHX11v6pml1PuVu3crUZiZeerD35Rwjizdgow==
                  2024-10-10 16:21:18 UTC249INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 56 43 44 5a 4e 53 59 45 56 54 47 4b 4b 46 53 44 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 51 53 61 70 39 4c 31 45 63 4a 72 55 48 4b 55 4d 43 43 31 56 41 65 63 4b 70 76 74 31 6c 4d 59 65 6f 31 55 2f 5a 67 59 4e 45 32 4e 34 55 47 74 41 66 6e 4e 56 75 34 36 4c 39 33 57 62 50 44 54 44 4c 51 46 45 63 47 65 64 65 58 4d 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a
                  Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>VCDZNSYEVTGKKFSD</RequestId><HostId>QSap9L1EcJrUHKUMCC1VAecKpvt1lMYeo1U/ZgYNE2N4UGtAfnNVu46L93WbPDTDLQFEcGedeXM=</HostId></Error>
                  2024-10-10 16:21:18 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.44976818.244.18.204433940C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-10-10 16:21:19 UTC604OUTGET /favicon.ico HTTP/1.1
                  Host: downloads.slack-edge.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://downloads.slack-edge.com/
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-10-10 16:21:20 UTC358INHTTP/1.1 403 Forbidden
                  Content-Type: application/xml
                  Transfer-Encoding: chunked
                  Connection: close
                  Date: Thu, 10 Oct 2024 16:21:20 GMT
                  Server: AmazonS3
                  X-Cache: Error from cloudfront
                  Via: 1.1 d025091c574ce1bcf1fefea59ac34f2c.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: FRA56-P11
                  X-Amz-Cf-Id: QuzHluV59vmBg9MJH3nc6ro8I7eUc4UCMRHUMU9ul4qWQ-rNpG970w==
                  2024-10-10 16:21:20 UTC249INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 48 33 4a 57 33 48 33 31 58 45 44 35 31 44 38 41 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 75 58 67 41 36 6e 45 6a 75 4a 46 53 47 4d 39 48 78 67 74 67 64 71 44 68 4c 6b 31 62 56 74 4e 73 33 68 53 5a 50 76 71 75 31 49 4f 2f 48 47 6d 5a 72 74 39 41 7a 5a 43 4b 75 74 57 59 73 6a 51 63 50 32 4d 31 2f 48 71 78 63 64 6b 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a
                  Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>H3JW3H31XED51D8A</RequestId><HostId>uXgA6nEjuJFSGM9HxgtgdqDhLk1bVtNs3hSZPvqu1IO/HGmZrt9AzZCKutWYsjQcP2M1/Hqxcdk=</HostId></Error>
                  2024-10-10 16:21:20 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:12:21:03
                  Start date:10/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:12:21:05
                  Start date:10/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2288,i,8993466432769708361,9923647099172993640,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:12:21:08
                  Start date:10/10/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://downloads.slack-edge.com"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly