Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D

Overview

General Information

Sample URL:http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5
Analysis ID:1411166
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3156 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,225315565658390162,13290618815348873061,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6432 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3DHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D HTTP/1.1Host: u2587569.ct.sendgrid.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: u2587569.ct.sendgrid.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3DAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: u2587569.ct.sendgrid.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Mon, 18 Mar 2024 16:25:29 GMTContent-Type: text/htmlContent-Length: 548Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,225315565658390162,13290618815348873061,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,225315565658390162,13290618815348873061,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
u2587569.ct.sendgrid.net
167.89.123.16
truefalse
    high
    www.google.com
    142.250.65.228
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://u2587569.ct.sendgrid.net/favicon.icofalse
          high
          http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3Dfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.65.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            167.89.123.16
            u2587569.ct.sendgrid.netUnited States
            11377SENDGRIDUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            192.168.2.5
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1411166
            Start date and time:2024-03-18 17:24:39 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 0s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/2@4/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.80.67, 142.251.32.110, 172.253.63.84, 34.104.35.123, 40.68.123.157, 23.206.121.22, 23.206.121.20, 23.206.121.28, 23.206.121.39, 23.206.121.48, 23.206.121.52, 192.229.211.108, 13.95.31.18, 13.85.23.206
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):548
            Entropy (8bit):4.688532577858027
            Encrypted:false
            SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
            MD5:370E16C3B7DBA286CFF055F93B9A94D8
            SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
            SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
            SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
            Malicious:false
            Reputation:low
            URL:http://u2587569.ct.sendgrid.net/favicon.ico
            Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 18, 2024 17:25:21.964478970 CET49675443192.168.2.4173.222.162.32
            Mar 18, 2024 17:25:22.042567015 CET49678443192.168.2.4104.46.162.224
            Mar 18, 2024 17:25:29.409842014 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.410223961 CET4973580192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.514647007 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:25:29.514764071 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.514971018 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.515415907 CET8049735167.89.123.16192.168.2.4
            Mar 18, 2024 17:25:29.515477896 CET4973580192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.620250940 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:25:29.620301008 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:25:29.677335024 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:29.782443047 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:25:29.857079029 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:25:31.577219963 CET49675443192.168.2.4173.222.162.32
            Mar 18, 2024 17:25:32.474225044 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.474261999 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.474350929 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.474843979 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.474855900 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.667500019 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.672638893 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.672658920 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.673938036 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.674050093 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.676642895 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.676711082 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.729567051 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.729578972 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:32.775686026 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:32.832425117 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:32.832487106 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:32.832720995 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:32.836571932 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:32.836585999 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.020174026 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.020342112 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.024264097 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.024275064 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.024544001 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.072933912 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.186263084 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.228269100 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.274676085 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.274782896 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.274854898 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.275075912 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.275091887 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.275105000 CET49740443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.275110006 CET4434974023.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.336635113 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.336694002 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.336760044 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.337932110 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.337945938 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.520392895 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.520467043 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.521595955 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.521610022 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.521855116 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.523158073 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.568232059 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.695558071 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.695732117 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.695775986 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.696902990 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.696933985 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:33.696948051 CET49741443192.168.2.423.51.58.94
            Mar 18, 2024 17:25:33.696954966 CET4434974123.51.58.94192.168.2.4
            Mar 18, 2024 17:25:42.660702944 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:42.660759926 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:25:42.660851955 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:42.737026930 CET49739443192.168.2.4142.250.65.228
            Mar 18, 2024 17:25:42.737052917 CET44349739142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:14.526269913 CET4973580192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:14.631445885 CET8049735167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:14.791929007 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:14.896682024 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:29.619831085 CET8049735167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:29.619920969 CET4973580192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:30.340966940 CET4973580192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:30.446557999 CET8049735167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:32.433722973 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:32.433813095 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.433901072 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:32.434408903 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:32.434443951 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.624408007 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.625128031 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:32.625174046 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.625507116 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.626513958 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:32.626574039 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:32.666960955 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:34.783823967 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:34.784023046 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:36.341876984 CET4973480192.168.2.4167.89.123.16
            Mar 18, 2024 17:26:36.446732044 CET8049734167.89.123.16192.168.2.4
            Mar 18, 2024 17:26:42.640045881 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:42.640126944 CET44349750142.250.65.228192.168.2.4
            Mar 18, 2024 17:26:42.640285015 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:44.408237934 CET49750443192.168.2.4142.250.65.228
            Mar 18, 2024 17:26:44.408268929 CET44349750142.250.65.228192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Mar 18, 2024 17:25:27.883023024 CET53597801.1.1.1192.168.2.4
            Mar 18, 2024 17:25:27.886534929 CET53616811.1.1.1192.168.2.4
            Mar 18, 2024 17:25:28.574636936 CET53617671.1.1.1192.168.2.4
            Mar 18, 2024 17:25:29.318048000 CET5946653192.168.2.41.1.1.1
            Mar 18, 2024 17:25:29.318463087 CET6115753192.168.2.41.1.1.1
            Mar 18, 2024 17:25:29.408477068 CET53594661.1.1.1192.168.2.4
            Mar 18, 2024 17:25:29.409022093 CET53611571.1.1.1192.168.2.4
            Mar 18, 2024 17:25:32.382900000 CET6379953192.168.2.41.1.1.1
            Mar 18, 2024 17:25:32.383258104 CET5283253192.168.2.41.1.1.1
            Mar 18, 2024 17:25:32.471611023 CET53637991.1.1.1192.168.2.4
            Mar 18, 2024 17:25:32.472145081 CET53528321.1.1.1192.168.2.4
            Mar 18, 2024 17:25:46.200500965 CET53500571.1.1.1192.168.2.4
            Mar 18, 2024 17:25:52.566946030 CET138138192.168.2.4192.168.2.255
            Mar 18, 2024 17:26:05.116199970 CET53582481.1.1.1192.168.2.4
            Mar 18, 2024 17:26:27.911259890 CET53598961.1.1.1192.168.2.4
            Mar 18, 2024 17:26:28.159960985 CET53603611.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 18, 2024 17:25:29.318048000 CET192.168.2.41.1.1.10x5703Standard query (0)u2587569.ct.sendgrid.netA (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.318463087 CET192.168.2.41.1.1.10xeeefStandard query (0)u2587569.ct.sendgrid.net65IN (0x0001)false
            Mar 18, 2024 17:25:32.382900000 CET192.168.2.41.1.1.10x36a6Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:32.383258104 CET192.168.2.41.1.1.10xaf57Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.123.16A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.118.118A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.118.28A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.118.35A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.123.147A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:29.408477068 CET1.1.1.1192.168.2.40x5703No error (0)u2587569.ct.sendgrid.net167.89.123.122A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:32.471611023 CET1.1.1.1192.168.2.40x36a6No error (0)www.google.com142.250.65.228A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:32.472145081 CET1.1.1.1192.168.2.40xaf57No error (0)www.google.com65IN (0x0001)false
            Mar 18, 2024 17:25:45.658631086 CET1.1.1.1192.168.2.40xebb1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 18, 2024 17:25:45.658631086 CET1.1.1.1192.168.2.40xebb1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 18, 2024 17:25:58.721512079 CET1.1.1.1192.168.2.40xd428No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 18, 2024 17:25:58.721512079 CET1.1.1.1192.168.2.40xd428No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 18, 2024 17:26:20.208825111 CET1.1.1.1192.168.2.40xeaf3No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 18, 2024 17:26:20.208825111 CET1.1.1.1192.168.2.40xeaf3No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 18, 2024 17:26:40.583522081 CET1.1.1.1192.168.2.40x3815No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 18, 2024 17:26:40.583522081 CET1.1.1.1192.168.2.40x3815No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • fs.microsoft.com
            • u2587569.ct.sendgrid.net
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449734167.89.123.1680928C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 18, 2024 17:25:29.514971018 CET700OUTGET /wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D HTTP/1.1
            Host: u2587569.ct.sendgrid.net
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Mar 18, 2024 17:25:29.620301008 CET335INHTTP/1.1 200 OK
            Server: nginx
            Date: Mon, 18 Mar 2024 16:25:29 GMT
            Content-Type: image/gif
            Content-Length: 43
            Connection: keep-alive
            Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
            Expires: Sat, 15 Jul 2000 05:00:00 GMT
            X-Robots-Tag: noindex, nofollow
            Data Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 ff ff ff 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
            Data Ascii: GIF89a!,D;
            Mar 18, 2024 17:25:29.677335024 CET653OUTGET /favicon.ico HTTP/1.1
            Host: u2587569.ct.sendgrid.net
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Referer: http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Mar 18, 2024 17:25:29.782443047 CET696INHTTP/1.1 404 Not Found
            Server: nginx
            Date: Mon, 18 Mar 2024 16:25:29 GMT
            Content-Type: text/html
            Content-Length: 548
            Connection: keep-alive
            Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
            Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
            Mar 18, 2024 17:26:14.791929007 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449735167.89.123.1680928C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 18, 2024 17:26:14.526269913 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44974023.51.58.94443
            TimestampBytes transferredDirectionData
            2024-03-18 16:25:33 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-18 16:25:33 UTC468INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/079C)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=183605
            Date: Mon, 18 Mar 2024 16:25:33 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44974123.51.58.94443
            TimestampBytes transferredDirectionData
            2024-03-18 16:25:33 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-18 16:25:33 UTC456INHTTP/1.1 200 OK
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0778)
            X-CID: 11
            Cache-Control: public, max-age=183617
            Date: Mon, 18 Mar 2024 16:25:33 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-03-18 16:25:33 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:17:25:25
            Start date:18/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:17:25:26
            Start date:18/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1992,i,225315565658390162,13290618815348873061,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:17:25:28
            Start date:18/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://u2587569.ct.sendgrid.net/wf/open?upn=u001.OgrAXKrVoxAzhoYmM0rTTC2KEFYqE2WcdiESCbPbMd0qTCqMFceF8-2BPhBtOCjcX9d4ExD3EGOU3sWpgUm9u6wum746qnqp0OU2gc809W70N9M69xtDACJ1mlK5dXXHXkrF-2Bb0jCIkATD1XZxxg5GHOz0vaPk8wRziXTyMHQsT7LRBVxX85TwPgH58vTt-2BLUaUPLWV015iVdCH2DtPkRuk0HXwbFMHgTsVssMuY2yr9g-3D
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly