Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ

Overview

General Information

Sample URL:https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
Analysis ID:1416906
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 1252 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2036,i,8529650298205695351,8277197342056155368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.18:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.18:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.18:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.190.132:443 -> 192.168.2.18:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.21.200:443 -> 192.168.2.18:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.132
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.132
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.132
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.132
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.132
Source: global trafficHTTP traffic detected: GET /w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ HTTP/1.1Host: liceogalois.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: liceogalois.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ravSZLykawa1Mbo&MD=oELhUP8x HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global trafficHTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: 60X-DeviceID: 01000A410900B03DX-BM-WindowsFlights: FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124117A5,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E,FX:12CDE644,FX:12D1574C,FX:12D281C4,FX:12E8312D,FX:12E85C75X-Search-TimeZone: Bias=-60; StandardBias=0; TimeZoneKeyName=W. Europe Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDYAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAaz2EfiSxIQchUkFT51VF0UyV31%2BLJN8ZHtk52gbEEpp3TH8PtaFvDS4VM3A8TlwfkNnfAjX2scRpVDF%2B%2B%2BnELcKaa5xkxHNlkoML3JIErq6A0pOMmBIkCTNVH/FL0mQ6soVX/nHBa0rsOLwD%2BzVjuFapzQTr9IDD4IhSItvLlkSbw5axW9/v3PGWZwc0j3kpLC9TDeo19NP8GFVLZpOv/S4x%2BEwbG9AXqJpuV15b8f1IXCKHdY2kZlnwxGI4GeFI53AWqJBt20TYbr72QGGwscxFGNnO/neRGjRK8R6JeofJL8eaChNCVctC9J%2BrK2VpyQS8Pub/TkhOcHbfCkr6VkDZgAACNy67dajKbNbqAGUvZoREtfqVQET1JnymyEHLJHZQZF2iWxCtjPKFXKNbH5hbWmo3VHLevIZiEKi/0BK9jW%2BPAN6Oz3svJojk7tvw%2B/xNhhRhPGoV4tDUZBEs3Pezm2g0h4wzhDq38zHbluXuhjwdigr1LB3bb4zFCY4KCPe7w3lWTAKIb25jpJvb8c5khTjeV9d2tp1HBo3NInIxwwM0UOdf2FLzqHbF0uJVhHxX1ZLCAGJajCFieZfaqJappksXITfdY/W47irDBqTM8nYOvcPqjAP5Px26YOCsfpOJEAicqP53A4X7B91VG7roj5JLIdM9M8wvv/0x4mA9trrK/PSjFJHlRwG/t0o8S%2ByjpYFh5rrDWazVSutsAW0krIawreyhljNctg%2BCttCBEz1bcsqdgT0zJhIQVTIOQUI2DrHRKeQ9X2cjUHieWUZ5Bhk8o/LUooKAe9G1cWgdajiRkUI%2BPe8N%2B%2B3L5U4BJ1TUXPMpPyx5neVzywOUI/suRUp74k3R/IBN2Qm%2BnJ3jG/c8hX51CJGclqxBeMcZiqGkx89IB3fNw2UcAcmrwYSvB7Pyitr2QE%3D%26p%3DX-Agent-DeviceId: 01000A410900B03DX-BM-CBT: 1711614574User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 710DACB0D94741BB87464334E59F0A24X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=B4BB39E5F80E411D94C438C0FA7ACF94&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=de&LUT=1707317051026&IPMH=6b344233&IPMID=1707317270835&HV=1707317277; ANON=A=680C1B1A649CBD64DD40EBFCFFFFFFFF; MUID=BC76BB0020D345C1A049A4820CB4C03C; MUIDB=BC76BB0020D345C1A049A4820CB4C03C
Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ravSZLykawa1Mbo&MD=oELhUP8x HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknownDNS traffic detected: queries for: liceogalois.co
Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 4784Host: login.live.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 08:28:58 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 08:28:59 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.18:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.18:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.18:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.190.132:443 -> 192.168.2.18:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.21.200:443 -> 192.168.2.18:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: classification engineClassification label: clean0.win@14/10@4/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2036,i,8529650298205695351,8277197342056155368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2036,i,8529650298205695351,8277197342056155368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://liceogalois.co/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
liceogalois.co
173.201.190.176
truefalse
    unknown
    www.google.com
    172.253.62.147
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://liceogalois.co/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      173.201.190.176
      liceogalois.coUnited States
      26496AS-26496-GO-DADDY-COM-LLCUSfalse
      172.253.62.147
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.18
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1416906
      Start date and time:2024-03-28 09:28:31 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 28s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsinteractivecookbook.jbs
      Sample URL:https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:14
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean0.win@14/10@4/5
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.251.167.94, 142.251.163.84, 142.251.16.102, 142.251.16.139, 142.251.16.138, 142.251.16.100, 142.251.16.101, 142.251.16.113, 34.104.35.123, 142.250.31.94, 142.251.167.138, 142.251.167.113, 142.251.167.100, 142.251.167.139, 142.251.167.101, 142.251.167.102
      • Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, login.live.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 07:28:59 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2675
      Entropy (8bit):3.9760529446402173
      Encrypted:false
      SSDEEP:48:8y5dnT5xMlqH4idAKZdA1rehwiZUklqehTy+3:8yzVxMlTgy
      MD5:74E8DB292831F4C44FF9C705132DC3F7
      SHA1:3165140B9FBBFB60D2804BAEBE810B899631ADDC
      SHA-256:F74CC9485BBDE4AB64096FE2BCCBC87EB20E3697ECE5C6C1CD405AB15618D234
      SHA-512:D872D8393C75A708272EAF96FD8B112A0B18CA357B03917B300197EE212CB73B2662A006CF5192048CE3683CBA02E0FE1C691387B4670042657B2A5C44D1A86D
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,..............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V|X.C.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 07:28:59 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.9941997822427333
      Encrypted:false
      SSDEEP:48:8b5dnT5xMlqH4idAKZdA1ceh/iZUkAQkqehQy+2:8bzVxMln9Q5y
      MD5:BDBA920FEDDDD1C5F7B3496719583FC2
      SHA1:988416180AAD6A9EA8842D8B8E561E531C86C903
      SHA-256:21212FB51EA0D15F7623BD08EF23C93A9175D204B1A130ADF2AFCD5EFA3D36BB
      SHA-512:D72EADC9840D0F46ECC307CDEE89639B688ED56D237DF6BF0988461654A4AE32F53ABF7872F0BC4B1F430CC83E2BFE0B260A27B81C42E530BDC8A8F30CEB549F
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,...............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V|X.C.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2691
      Entropy (8bit):4.000543694913458
      Encrypted:false
      SSDEEP:48:8XR5dnT5xMSH4idAKZdA14Aeh7sFiZUkmgqeh7suy+BX:8hzVxMZnsy
      MD5:860036DAB6E7FF54227450C270C0D690
      SHA1:AF1BEC3DF07058C9CE0907C957D8CDA34DFA9AE4
      SHA-256:D06967660E26AC267ED5BB7F0B2F39C6DC8F2E1C70D928220C71886B15A3EB01
      SHA-512:CDA0DA388BFD960A0E7A9CA42B5EDD02A430173EC970EEE5DDBE6678CDC3C7820E2381B13A92C9F4FCB6479217D0165E5AF9A3079302365FA346AB9824ED949E
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....?.4 ?.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.R.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 07:28:59 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):3.990901485385675
      Encrypted:false
      SSDEEP:48:8H5dnT5xMlqH4idAKZdA1JehDiZUkwqehUy+R:8HzVxMlS2y
      MD5:9E13DAC78BE79785B1E66A1DB2ADE0FE
      SHA1:09182A6010AB963BD3FF70EB4A288ECAEDE6E1B4
      SHA-256:565386779B0D34709468FFFEB47CF5040F7318183BBD5CDBC3516F9F9816443C
      SHA-512:5D2D57E6016703F477BDD78BE1D202E0A21FDF10436C416D44B483DC67C7D4499A5ECD78E49E8E55A01A4021B151D3A490CA2FEC34F2C34FAC2B057C60F265B7
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,..............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V|X.C.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 07:28:59 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):3.979115391923026
      Encrypted:false
      SSDEEP:48:8K5dnT5xMlqH4idAKZdA1XehBiZUk1W1qehqy+C:8KzVxMly9Ky
      MD5:1154DFEA96387BB717D5589F9C411C98
      SHA1:589399A5766D544481C6A9125295AAC3110CC31C
      SHA-256:9A15C0FF804BE58063234F251EFFC1B08CE3561CB4E084FACD5B645ADCC5AD15
      SHA-512:0D89522D55A8998FD29C2A5E7E691D8EF631FD9BE62D0C6764C0C13988A4F388B85520539610C85A662606AD66956ECFAEA1CA91378C7D6F7686E0E8A52435F4
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,..............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V|X.C.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 07:28:59 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.9894333139551983
      Encrypted:false
      SSDEEP:48:8j15dnT5xMlqH4idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbsy+yT+:8j1zVxMlGT/TbxWOvTbsy7T
      MD5:F2F4FFBF2D3FDA54FDCF9B7F0536DD2B
      SHA1:932412AF101404AD6249B11E660CF53DD091D24D
      SHA-256:0BC35FC4F29F60D854CB63DE5EC134F869707A561D42E45B32DF8185ADB15845
      SHA-512:681E7EA525CE2BB3F40201D63C30AAA09C5018787B198EBA0571B0CF76BCB0F70870FC47BD89FFBFF7A131A022D8675B8ED07D596598B207217DDA6FF75969AD
      Malicious:false
      Reputation:low
      Preview:L..................F.@.. ...$+.,....xF.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I|X.C....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X.C....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V|X.C....M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V|X.C...........................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V|X.C.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z5.L.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text
      Category:downloaded
      Size (bytes):315
      Entropy (8bit):5.0572271090563765
      Encrypted:false
      SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
      MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
      SHA1:A82190FC530C265AA40A045C21770D967F4767B8
      SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
      SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
      Malicious:false
      Reputation:low
      URL:https://liceogalois.co/favicon.ico
      Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:HTML document, ASCII text
      Category:downloaded
      Size (bytes):315
      Entropy (8bit):5.0572271090563765
      Encrypted:false
      SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
      MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
      SHA1:A82190FC530C265AA40A045C21770D967F4767B8
      SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
      SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
      Malicious:false
      Reputation:low
      URL:https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
      Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Mar 28, 2024 09:28:58.441138983 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.441209078 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.441312075 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.441587925 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.441610098 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.442055941 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.442090988 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.442154884 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.442358971 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.442368984 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.910640001 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.910640955 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.910926104 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.910962105 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.911031961 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.911063910 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.911900043 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.911956072 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.911967993 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.912018061 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.913353920 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.913420916 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.914167881 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.914237976 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.914520979 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.914532900 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:58.960901976 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.960906982 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:58.960927963 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.010080099 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.066029072 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.066118956 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.066205978 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.066814899 CET49692443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.066839933 CET44349692173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.119232893 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.164238930 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.271374941 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.271481037 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:28:59.271574974 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.272330046 CET49693443192.168.2.18173.201.190.176
      Mar 28, 2024 09:28:59.272353888 CET44349693173.201.190.176192.168.2.18
      Mar 28, 2024 09:29:03.201905012 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.201945066 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.202053070 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.202269077 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.202282906 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.421701908 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.421967030 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.421984911 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.423002958 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.423075914 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.424108982 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.424165010 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.476931095 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:03.476942062 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:03.523901939 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:05.100224972 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.100260973 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.100343943 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.101974010 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.101988077 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.299680948 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.299839020 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.303236961 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.303245068 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.303541899 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.340138912 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.384229898 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.484308004 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.484378099 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.484463930 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.484535933 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.484554052 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.484568119 CET49701443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.484572887 CET4434970123.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.518393040 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.518424034 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.518616915 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.518830061 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.518842936 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.713148117 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.713242054 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.714729071 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.714740038 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.714947939 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.716262102 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.760230064 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.902316093 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.902374983 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.902435064 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.903372049 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.903388023 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:05.903400898 CET49702443192.168.2.1823.33.180.114
      Mar 28, 2024 09:29:05.903407097 CET4434970223.33.180.114192.168.2.18
      Mar 28, 2024 09:29:12.181366920 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.181404114 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:12.181503057 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.182931900 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.182952881 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:12.473215103 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:12.738393068 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:12.738477945 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.741425991 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.741440058 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:12.741744041 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:12.776881933 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:12.792886019 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.801165104 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:12.844238997 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.273818016 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.273838997 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.273842096 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.273937941 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.273972034 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.274048090 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.274075031 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.274092913 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.274132013 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.274374962 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.274445057 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.274466038 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.274503946 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.285909891 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.285932064 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.285984039 CET49703443192.168.2.1840.68.123.157
      Mar 28, 2024 09:29:13.285990953 CET4434970340.68.123.157192.168.2.18
      Mar 28, 2024 09:29:13.382936954 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:13.436822891 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:13.436899900 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:13.436966896 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:14.546530962 CET49700443192.168.2.18172.253.62.147
      Mar 28, 2024 09:29:14.546576977 CET44349700172.253.62.147192.168.2.18
      Mar 28, 2024 09:29:14.593003988 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:17.000912905 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:19.590369940 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:19.893899918 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:20.501014948 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:21.710922956 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:21.806885958 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:24.120887041 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:28.930876017 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:31.406902075 CET49673443192.168.2.18204.79.197.203
      Mar 28, 2024 09:29:35.478624105 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:35.478658915 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:35.478739023 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:35.479835987 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:35.479851007 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:35.982578039 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:35.982707024 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.020055056 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.020073891 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.020309925 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.021457911 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.021501064 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.021519899 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.429963112 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.429989100 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.430030107 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.430094957 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.430107117 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.430170059 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.437545061 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.437565088 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.437575102 CET49704443192.168.2.1820.190.190.132
      Mar 28, 2024 09:29:36.437580109 CET4434970420.190.190.132192.168.2.18
      Mar 28, 2024 09:29:36.619256020 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.619303942 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.619384050 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.621258974 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.621272087 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.917023897 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.917253971 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.917697906 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.917757988 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.961991072 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.962007999 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.962270975 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:36.962325096 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.964181900 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:36.964210033 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:37.184243917 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:37.184261084 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:37.184317112 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:37.184364080 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:37.184401035 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:37.187474966 CET49705443192.168.2.1813.107.21.200
      Mar 28, 2024 09:29:37.187505960 CET4434970513.107.21.200192.168.2.18
      Mar 28, 2024 09:29:38.538095951 CET49679443192.168.2.1852.182.141.63
      Mar 28, 2024 09:29:47.473058939 CET4968980192.168.2.1872.21.81.240
      Mar 28, 2024 09:29:47.568008900 CET804968972.21.81.240192.168.2.18
      Mar 28, 2024 09:29:47.568085909 CET4968980192.168.2.1872.21.81.240
      Mar 28, 2024 09:29:49.761646032 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:49.761693954 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:49.761790991 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:49.762244940 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:49.762255907 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.283617973 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.283760071 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.285023928 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.285033941 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.285270929 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.286828041 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.332241058 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.790935993 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.790971994 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.791071892 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.791157007 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.791194916 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.791213036 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.791222095 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.791274071 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.818753958 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.818777084 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:29:50.818787098 CET49706443192.168.2.1820.114.59.183
      Mar 28, 2024 09:29:50.818793058 CET4434970620.114.59.183192.168.2.18
      Mar 28, 2024 09:30:03.166955948 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:03.166989088 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.167151928 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:03.167404890 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:03.167414904 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.391060114 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.391400099 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:03.391413927 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.396559000 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.396863937 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:03.400274038 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:03.453943014 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:13.416390896 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:13.416471958 CET44349708172.253.62.147192.168.2.18
      Mar 28, 2024 09:30:13.416603088 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:14.550676107 CET49708443192.168.2.18172.253.62.147
      Mar 28, 2024 09:30:14.550702095 CET44349708172.253.62.147192.168.2.18
      TimestampSource PortDest PortSource IPDest IP
      Mar 28, 2024 09:28:58.307029963 CET5755753192.168.2.181.1.1.1
      Mar 28, 2024 09:28:58.307179928 CET5208353192.168.2.181.1.1.1
      Mar 28, 2024 09:28:58.401122093 CET53636841.1.1.1192.168.2.18
      Mar 28, 2024 09:28:58.405788898 CET53520831.1.1.1192.168.2.18
      Mar 28, 2024 09:28:58.438863039 CET53575571.1.1.1192.168.2.18
      Mar 28, 2024 09:28:58.461013079 CET53610701.1.1.1192.168.2.18
      Mar 28, 2024 09:28:59.053258896 CET53526801.1.1.1192.168.2.18
      Mar 28, 2024 09:29:03.105802059 CET6531153192.168.2.181.1.1.1
      Mar 28, 2024 09:29:03.105961084 CET5203353192.168.2.181.1.1.1
      Mar 28, 2024 09:29:03.200658083 CET53653111.1.1.1192.168.2.18
      Mar 28, 2024 09:29:03.200993061 CET53520331.1.1.1192.168.2.18
      Mar 28, 2024 09:29:16.058474064 CET53530561.1.1.1192.168.2.18
      Mar 28, 2024 09:29:34.910011053 CET53594751.1.1.1192.168.2.18
      Mar 28, 2024 09:29:57.510211945 CET53590171.1.1.1192.168.2.18
      Mar 28, 2024 09:29:58.390558958 CET53589491.1.1.1192.168.2.18
      Mar 28, 2024 09:30:19.803742886 CET138138192.168.2.18192.168.2.255
      Mar 28, 2024 09:30:26.265151024 CET53546771.1.1.1192.168.2.18
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Mar 28, 2024 09:28:58.307029963 CET192.168.2.181.1.1.10x7b9dStandard query (0)liceogalois.coA (IP address)IN (0x0001)false
      Mar 28, 2024 09:28:58.307179928 CET192.168.2.181.1.1.10x4debStandard query (0)liceogalois.co65IN (0x0001)false
      Mar 28, 2024 09:29:03.105802059 CET192.168.2.181.1.1.10x62d6Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.105961084 CET192.168.2.181.1.1.10x107dStandard query (0)www.google.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Mar 28, 2024 09:28:58.438863039 CET1.1.1.1192.168.2.180x7b9dNo error (0)liceogalois.co173.201.190.176A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.147A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.99A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.105A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.103A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.106A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200658083 CET1.1.1.1192.168.2.180x62d6No error (0)www.google.com172.253.62.104A (IP address)IN (0x0001)false
      Mar 28, 2024 09:29:03.200993061 CET1.1.1.1192.168.2.180x107dNo error (0)www.google.com65IN (0x0001)false
      • liceogalois.co
      • https:
      • fs.microsoft.com
      • slscr.update.microsoft.com
      • login.live.com
      • www.bing.com
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.1849692173.201.190.1764431252C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-03-28 08:28:58 UTC751OUTGET /w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ HTTP/1.1
      Host: liceogalois.co
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      sec-ch-ua-platform: "Windows"
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Sec-Fetch-Site: none
      Sec-Fetch-Mode: navigate
      Sec-Fetch-User: ?1
      Sec-Fetch-Dest: document
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-03-28 08:28:59 UTC164INHTTP/1.1 404 Not Found
      Date: Thu, 28 Mar 2024 08:28:58 GMT
      Server: Apache
      Content-Length: 315
      Connection: close
      Content-Type: text/html; charset=iso-8859-1
      2024-03-28 08:28:59 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
      Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.1849693173.201.190.1764431252C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      2024-03-28 08:28:59 UTC678OUTGET /favicon.ico HTTP/1.1
      Host: liceogalois.co
      Connection: keep-alive
      sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
      sec-ch-ua-mobile: ?0
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      sec-ch-ua-platform: "Windows"
      Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
      Sec-Fetch-Site: same-origin
      Sec-Fetch-Mode: no-cors
      Sec-Fetch-Dest: image
      Referer: https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
      Accept-Encoding: gzip, deflate, br
      Accept-Language: en-US,en;q=0.9
      2024-03-28 08:28:59 UTC164INHTTP/1.1 404 Not Found
      Date: Thu, 28 Mar 2024 08:28:59 GMT
      Server: Apache
      Content-Length: 315
      Connection: close
      Content-Type: text/html; charset=iso-8859-1
      2024-03-28 08:28:59 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
      Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.184970123.33.180.114443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:05 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-03-28 08:29:05 UTC468INHTTP/1.1 200 OK
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      Content-Type: application/octet-stream
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      Server: ECAcc (chd/073D)
      X-CID: 11
      X-Ms-ApiVersion: Distribute 1.2
      X-Ms-Region: prod-eus2-z1
      Cache-Control: public, max-age=254051
      Date: Thu, 28 Mar 2024 08:29:05 GMT
      Connection: close
      X-CID: 2


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.184970223.33.180.114443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:05 UTC239OUTGET /fs/windows/config.json HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      Accept-Encoding: identity
      If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
      Range: bytes=0-2147483646
      User-Agent: Microsoft BITS/7.8
      Host: fs.microsoft.com
      2024-03-28 08:29:05 UTC531INHTTP/1.1 200 OK
      Content-Type: application/octet-stream
      Last-Modified: Tue, 16 May 2017 22:58:00 GMT
      ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
      ApiVersion: Distribute 1.1
      Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
      X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
      Cache-Control: public, max-age=254044
      Date: Thu, 28 Mar 2024 08:29:05 GMT
      Content-Length: 55
      Connection: close
      X-CID: 2
      2024-03-28 08:29:05 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
      Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.184970340.68.123.157443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:12 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ravSZLykawa1Mbo&MD=oELhUP8x HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
      Host: slscr.update.microsoft.com
      2024-03-28 08:29:13 UTC560INHTTP/1.1 200 OK
      Cache-Control: no-cache
      Pragma: no-cache
      Content-Type: application/octet-stream
      Expires: -1
      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
      ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
      MS-CorrelationId: b64a8076-a19d-4e82-b0a9-39c89b5e3df3
      MS-RequestId: b8740d20-3223-4105-ab69-8232b675b6ad
      MS-CV: MvvfRv7ZbkO9DxBx.0
      X-Microsoft-SLSClientCache: 2880
      Content-Disposition: attachment; filename=environment.cab
      X-Content-Type-Options: nosniff
      Date: Thu, 28 Mar 2024 08:29:12 GMT
      Connection: close
      Content-Length: 24490
      2024-03-28 08:29:13 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
      Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
      2024-03-28 08:29:13 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
      Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      5192.168.2.184970420.190.190.132443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:36 UTC422OUTPOST /RST2.srf HTTP/1.0
      Connection: Keep-Alive
      Content-Type: application/soap+xml
      Accept: */*
      User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
      Content-Length: 4784
      Host: login.live.com
      2024-03-28 08:29:36 UTC4784OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
      Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
      2024-03-28 08:29:36 UTC569INHTTP/1.1 200 OK
      Cache-Control: no-store, no-cache
      Pragma: no-cache
      Content-Type: application/soap+xml; charset=utf-8
      Expires: Thu, 28 Mar 2024 08:28:36 GMT
      P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
      Referrer-Policy: strict-origin-when-cross-origin
      x-ms-route-info: C539_BAY
      x-ms-request-id: fb5a504a-1702-4592-8851-2e7e78225c79
      PPServer: PPV: 30 H: PH1PEPF00011D00 V: 0
      X-Content-Type-Options: nosniff
      Strict-Transport-Security: max-age=31536000
      X-XSS-Protection: 1; mode=block
      Date: Thu, 28 Mar 2024 08:29:36 GMT
      Connection: close
      Content-Length: 11153
      2024-03-28 08:29:36 UTC11153INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
      Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      6192.168.2.184970513.107.21.200443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:36 UTC2734OUTGET /client/config?cc=CH&setlang=en-CH HTTP/1.1
      X-Search-CortanaAvailableCapabilities: None
      X-Search-SafeSearch: Moderate
      Accept-Encoding: gzip, deflate
      X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
      X-UserAgeClass: Unknown
      X-BM-Market: CH
      X-BM-DateFormat: dd/MM/yyyy
      X-Device-OSSKU: 48
      X-BM-DTZ: 60
      X-DeviceID: 01000A410900B03D
      X-BM-WindowsFlights: FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124117A5,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E,FX:12CDE644,FX:12D1574C,FX:12D281C4,FX:12E8312D,FX:12E85C75
      X-Search-TimeZone: Bias=-60; StandardBias=0; TimeZoneKeyName=W. Europe Standard Time
      X-BM-Theme: 000000;0078d7
      X-Search-RPSToken: t%3DEwDYAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAaz2EfiSxIQchUkFT51VF0UyV31%2BLJN8ZHtk52gbEEpp3TH8PtaFvDS4VM3A8TlwfkNnfAjX2scRpVDF%2B%2B%2BnELcKaa5xkxHNlkoML3JIErq6A0pOMmBIkCTNVH/FL0mQ6soVX/nHBa0rsOLwD%2BzVjuFapzQTr9IDD4IhSItvLlkSbw5axW9/v3PGWZwc0j3kpLC9TDeo19NP8GFVLZpOv/S4x%2BEwbG9AXqJpuV15b8f1IXCKHdY2kZlnwxGI4GeFI53AWqJBt20TYbr72QGGwscxFGNnO/neRGjRK8R6JeofJL8eaChNCVctC9J%2BrK2VpyQS8Pub/TkhOcHbfCkr6VkDZgAACNy67dajKbNbqAGUvZoREtfqVQET1JnymyEHLJHZQZF2iWxCtjPKFXKNbH5hbWmo3VHLevIZiEKi/0BK9jW%2BPAN6Oz3svJojk7tvw%2B/xNhhRhPGoV4tDUZBEs3Pezm2g0h4wzhDq38zHbluXuhjwdigr1LB3bb4zFCY4KCPe7w3lWTAKIb25jpJvb8c5khTjeV9d2tp1HBo3NInIxwwM0UOdf2FLzqHbF0uJVhHxX1ZLCAGJajCFieZfaqJappksXITfdY/W47irDBqTM8nYOvcPqjAP5Px26YOCsfpOJEAicqP53A4X7B91VG7roj5JLIdM9M8wvv/0x4mA9trrK/PSjFJHlRwG/t0o8S%2ByjpYFh5rrDWazVSutsAW0krIawreyhljNctg%2BCttCBEz1bcsqdgT0zJhIQVTIOQUI2DrHRKeQ9X2cjUHieWUZ5Bhk8o/LUooKAe9G1cWgdajiRkUI%2BPe8N%2B%2B3L5U4BJ1TUXPMpPyx5neVzywOUI/suRUp74k3R/IBN2Qm%2BnJ3jG/c8hX51CJGclqxBeMcZiqGkx89IB3fNw2UcAcmrwYSvB7Pyitr2QE%3D%26p%3D
      X-Agent-DeviceId: 01000A410900B03D
      X-BM-CBT: 1711614574
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
      X-Device-isOptin: false
      Accept-language: en-GB, en, en-US
      X-Device-Touch: false
      X-Device-ClientSession: 710DACB0D94741BB87464334E59F0A24
      X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
      Host: www.bing.com
      Connection: Keep-Alive
      Cookie: SRCHUID=V=2&GUID=B4BB39E5F80E411D94C438C0FA7ACF94&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=de&LUT=1707317051026&IPMH=6b344233&IPMID=1707317270835&HV=1707317277; ANON=A=680C1B1A649CBD64DD40EBFCFFFFFFFF; MUID=BC76BB0020D345C1A049A4820CB4C03C; MUIDB=BC76BB0020D345C1A049A4820CB4C03C
      2024-03-28 08:29:37 UTC1508INHTTP/1.1 200 OK
      Cache-Control: private
      Content-Length: 2215
      Content-Type: application/json; charset=utf-8
      P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND"
      Set-Cookie: _EDGE_S=SID=07FE00054B0564E502CD14554A0765A6&mkt=de-ch; domain=.bing.com; path=/; HttpOnly
      Set-Cookie: MUIDB=BC76BB0020D345C1A049A4820CB4C03C; expires=Tue, 22-Apr-2025 08:29:37 GMT; path=/; HttpOnly
      Set-Cookie: SRCHHPGUSR=SRCHLANG=en&LUT=1707317051026&IPMH=6b344233&IPMID=1707317270835&HV=1707317277; domain=.bing.com; expires=Tue, 22-Apr-2025 08:29:37 GMT; path=/; secure; SameSite=None
      Set-Cookie: WLS=C=0000000000000000&N=; domain=.bing.com; path=/; secure; SameSite=None
      Set-Cookie: _SS=SID=07FE00054B0564E502CD14554A0765A6; domain=.bing.com; path=/; secure; SameSite=None
      X-EventID: 66052a713f854fbf82473fa975f908da
      UserAgentReductionOptOut: A7kgTC5xdZ2WIVGZEfb1hUoNuvjzOZX3VIV/BA6C18kQOOF50Q0D3oWoAm49k3BQImkujKILc7JmPysWk3CSjwUAAACMeyJvcmlnaW4iOiJodHRwczovL3d3dy5iaW5nLmNvbTo0NDMiLCJmZWF0dXJlIjoiU2VuZEZ1bGxVc2VyQWdlbnRBZnRlclJlZHVjdGlvbiIsImV4cGlyeSI6MTY4NDg4NjM5OSwiaXNTdWJkb21haW4iOnRydWUsImlzVGhpcmRQYXJ0eSI6dHJ1ZX0=
      X-XSS-Protection: 0
      X-Cache: CONFIG_NOCACHE
      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
      X-MSEdge-Ref: Ref A: AC99C8E65B1C4003B564F2D6D8DCC845 Ref B: BL2EDGE1908 Ref C: 2024-03-28T08:29:37Z
      Date: Thu, 28 Mar 2024 08:29:37 GMT
      Connection: close
      2024-03-28 08:29:37 UTC2215INData Raw: 7b 22 76 65 72 73 69 6f 6e 22 3a 31 2c 22 63 6f 6e 66 69 67 22 3a 7b 22 46 65 61 74 75 72 65 43 6f 6e 66 69 67 22 3a 7b 22 53 65 61 72 63 68 42 6f 78 49 62 65 61 6d 50 6f 69 6e 74 65 72 4f 6e 48 6f 76 65 72 22 3a 7b 22 76 61 6c 75 65 22 3a 74 72 75 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 68 6f 77 53 65 61 72 63 68 47 6c 79 70 68 4c 65 66 74 4f 66 53 65 61 72 63 68 42 6f 78 22 3a 7b 22 76 61 6c 75 65 22 3a 74 72 75 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 65 61 72 63 68 42 6f 78 55 73 65 53 65 61 72 63 68 49 63 6f 6e 41 74 52 65 73 74 22 3a 7b 22 76 61 6c 75 65 22 3a 66 61 6c 73 65 2c 22 66 65 61 74 75 72 65 22 3a 22 22 7d 2c 22 53 65 61 72 63 68 42 75 74 74 6f 6e 55 73 65 53 65 61 72 63 68 49 63 6f 6e 22 3a 7b 22 76 61 6c 75 65
      Data Ascii: {"version":1,"config":{"FeatureConfig":{"SearchBoxIbeamPointerOnHover":{"value":true,"feature":""},"ShowSearchGlyphLeftOfSearchBox":{"value":true,"feature":""},"SearchBoxUseSearchIconAtRest":{"value":false,"feature":""},"SearchButtonUseSearchIcon":{"value


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      7192.168.2.184970620.114.59.183443
      TimestampBytes transferredDirectionData
      2024-03-28 08:29:50 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ravSZLykawa1Mbo&MD=oELhUP8x HTTP/1.1
      Connection: Keep-Alive
      Accept: */*
      User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
      Host: slscr.update.microsoft.com
      2024-03-28 08:29:50 UTC560INHTTP/1.1 200 OK
      Cache-Control: no-cache
      Pragma: no-cache
      Content-Type: application/octet-stream
      Expires: -1
      Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
      ETag: "Mx1RoJH/qEwpWfKllx7sbsl28AuERz5IYdcsvtTJcgM=_2160"
      MS-CorrelationId: 7b723b42-db61-4c1f-bcab-b4691d861833
      MS-RequestId: 9835535f-35a8-4f2a-a98b-9271c884c8f2
      MS-CV: s7LMwGEhgkKBzhuh.0
      X-Microsoft-SLSClientCache: 2160
      Content-Disposition: attachment; filename=environment.cab
      X-Content-Type-Options: nosniff
      Date: Thu, 28 Mar 2024 08:29:49 GMT
      Connection: close
      Content-Length: 25457
      2024-03-28 08:29:50 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 51 22 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 db 8e 00 00 14 00 00 00 00 00 10 00 51 22 00 00 20 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 f3 43 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 0d 92 6f db e5 21 f3 43 43 4b ed 5a 09 38 55 5b df 3f 93 99 90 29 99 e7 29 ec 73 cc 4a 66 32 cf 84 32 64 c8 31 c7 11 52 38 87 90 42 66 09 99 87 32 0f 19 0a 09 51 a6 a8 08 29 53 86 4a 52 84 50 df 46 83 ba dd 7b df fb 7e ef 7d ee 7d bf ef 9e e7 d9 67 ef 35 ee b5 fe eb 3f ff b6 96 81 a2 0a 04 fc 31 40 21 5b 3f a5 ed 1b 04 0e 85 42 a0 10 04 64 12 6c a5 de aa a1 d8 ea f3 58 01 f2 f5 67 0b 5e 9b bd e8 a0 90 1d bf 40 88 9d eb 49 b4 87 9b ab 8b 9d 2b 46 c8 c7 c5 19 92
      Data Ascii: MSCFQ"DQ" AdCenvironment.cabo!CCKZ8U[?))sJf22d1R8Bf2Q)SJRPF{~}}g5?1@![?BdlXg^@I+F
      2024-03-28 08:29:50 UTC9633INData Raw: 21 6f b3 eb a6 cc f5 31 be cf 05 e2 a9 fe fa 57 6d 19 30 b3 c2 c5 66 c9 6a df f5 e7 f0 78 bd c7 a8 9e 25 e3 f9 bc ed 6b 54 57 08 2b 51 82 44 12 fb b9 53 8c cc f4 60 12 8a 76 cc 40 40 41 9b dc 5c 17 ff 5c f9 5e 17 35 98 24 56 4b 74 ef 42 10 c8 af bf 7f c6 7f f2 37 7d 5a 3f 1c f2 99 79 4a 91 52 00 af 38 0f 17 f5 2f 79 81 65 d9 a9 b5 6b e4 c7 ce f6 ca 7a 00 6f 4b 30 44 24 22 3c cf ed 03 a5 96 8f 59 29 bc b6 fd 04 e1 70 9f 32 4a 27 fd 55 af 2f fe b6 e5 8e 33 bb 62 5f 9a db 57 40 e9 f1 ce 99 66 90 8c ff 6a 62 7f dd c5 4a 0b 91 26 e2 39 ec 19 4a 71 63 9d 7b 21 6d c3 9c a3 a2 3c fa 7f 7d 96 6a 90 78 a6 6d d2 e1 9c f9 1d fc 38 d8 94 f4 c6 a5 0a 96 86 a4 bd 9e 1a ae 04 42 83 b8 b5 80 9b 22 38 20 b5 25 e5 64 ec f7 f4 bf 7e 63 59 25 0f 7a 2e 39 57 76 a2 71 aa 06 8a
      Data Ascii: !o1Wm0fjx%kTW+QDS`v@@A\\^5$VKtB7}Z?yJR8/yekzoK0D$"<Y)p2J'U/3b_W@fjbJ&9Jqc{!m<}jxm8B"8 %d~cY%z.9Wvq


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:09:28:56
      Start date:28/03/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQ&usg=AOvVaw0gc8NfeodrA8Seq_rkAzeZ
      Imagebase:0x7ff728d30000
      File size:3'242'272 bytes
      MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:1
      Start time:09:28:57
      Start date:28/03/2024
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2036,i,8529650298205695351,8277197342056155368,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff728d30000
      File size:3'242'272 bytes
      MD5 hash:83395EAB5B03DEA9720F8D7AC0D15CAA
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      No disassembly