Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://repository.edicomnet.com

Overview

General Information

Sample URL:http://repository.edicomnet.com
Analysis ID:1417127
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4048 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2332,i,7333287129093996952,18099021527419356767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 7112 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://repository.edicomnet.com" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://repository.edicomnet.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49717 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 168.61.215.74
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: repository.edicomnet.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: repository.edicomnet.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://repository.edicomnet.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: repository.edicomnet.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbiddendate: Thu, 28 Mar 2024 15:24:58 GMTserver: Apachex-frame-options: SAMEORIGINstrict-transport-security: max-age=600; includeSubdomains;preloadcontent-length: 321content-type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 2f 0a 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access /on this server.</p><p>Additionally, a 403 Forbiddenerror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Founddate: Thu, 28 Mar 2024 15:24:58 GMTserver: Apachex-frame-options: SAMEORIGINstrict-transport-security: max-age=600; includeSubdomains;preloadcontent-length: 328content-type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /favicon.ico was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49717 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2332,i,7333287129093996952,18099021527419356767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://repository.edicomnet.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2332,i,7333287129093996952,18099021527419356767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://repository.edicomnet.com0%Avira URL Cloudsafe
http://repository.edicomnet.com0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://repository.edicomnet.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.253.122.103
truefalse
    high
    repository.edicomnet.com
    212.49.145.8
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://repository.edicomnet.com/false
          unknown
          http://repository.edicomnet.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          212.49.145.8
          repository.edicomnet.comSpain
          31262EDICOMESfalse
          172.253.122.103
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.7
          192.168.2.16
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1417127
          Start date and time:2024-03-28 16:23:54 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 19s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://repository.edicomnet.com
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:17
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/4@4/6
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.251.167.94, 142.251.163.84, 142.251.111.102, 142.251.111.101, 142.251.111.139, 142.251.111.138, 142.251.111.100, 142.251.111.113, 34.104.35.123, 52.165.165.26, 72.21.81.240, 23.199.71.136, 23.199.71.185, 192.229.211.108, 13.95.31.18, 20.166.126.56, 142.251.111.94
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, time.windows.com, a767.dspw65.akamai.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):321
          Entropy (8bit):5.0623370116568465
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwIgsozEr6VyF02xxdGzKQFEHcLgWugszvjsKtgsg93wzRbKqD:J0+oxBgsozR4F0+dgKxfWugszvjsKtg0
          MD5:85CB5F9CB8DB1C144F09CBD6B1D31805
          SHA1:336074789EF5B62C8893CE6E46AFC9464E0139B9
          SHA-256:46817911664A4E3DC2A367C5A5E3891568A027AEF37ADB77F702597290E687EF
          SHA-512:E69A7950AEFD5D54493CF82913F0345B1B01E109D76900DFF275EC10B5DBEDB15C7461F97C961D002A0F1064177A161D668AE0DD179E95F428533608E4C0CFD9
          Malicious:false
          Reputation:low
          URL:http://repository.edicomnet.com/
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access /.on this server.</p>.<p>Additionally, a 403 Forbidden.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):328
          Entropy (8bit):5.076711494053487
          Encrypted:false
          SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3ezJLM4KCezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxy17ezZfCzjsKtg0
          MD5:301FA7CEB5B3C291D4BBEEE953048686
          SHA1:758D921EFD60D4E9F0F6D77648CCC500C8611FEA
          SHA-256:6B62A3658AD247E8F30D3E9F35DA5E00FFAC1EA09785BD1F0A9830F659CF01DA
          SHA-512:8716CF8748B7DB5754A1DB73F6175B152672144EFA0FD866A17F9ABFAF18676A286CCE27FD4E08E6F17E177C1E14631D97E3C2A5C10FE82316CA03DD551B6893
          Malicious:false
          Reputation:low
          URL:http://repository.edicomnet.com/favicon.ico
          Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL /favicon.ico was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 16:24:46.904668093 CET49671443192.168.2.7204.79.197.203
          Mar 28, 2024 16:24:49.310807943 CET49671443192.168.2.7204.79.197.203
          Mar 28, 2024 16:24:49.420192957 CET49674443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:49.420437098 CET49675443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:49.590008974 CET49672443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:53.601897955 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:24:54.159390926 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:24:54.248342037 CET49671443192.168.2.7204.79.197.203
          Mar 28, 2024 16:24:54.951461077 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:24:56.453541040 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:24:57.844634056 CET4971080192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:57.845114946 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:57.988065004 CET4971280192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.022505999 CET8049711212.49.145.8192.168.2.7
          Mar 28, 2024 16:24:58.022624016 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.022876978 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.030848026 CET8049710212.49.145.8192.168.2.7
          Mar 28, 2024 16:24:58.030930042 CET4971080192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.174115896 CET8049712212.49.145.8192.168.2.7
          Mar 28, 2024 16:24:58.174185038 CET4971280192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.205419064 CET8049711212.49.145.8192.168.2.7
          Mar 28, 2024 16:24:58.245326042 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.314645052 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.496010065 CET8049711212.49.145.8192.168.2.7
          Mar 28, 2024 16:24:58.627151012 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.627198935 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.627298117 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.627554893 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.627566099 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.654241085 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:24:58.841563940 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.842035055 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.842050076 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.843894005 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.843975067 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.845675945 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.845912933 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:58.974714994 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:58.974735022 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:24:59.045902967 CET49674443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:59.045941114 CET49675443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:59.155272007 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:24:59.358412981 CET49672443192.168.2.7104.98.116.138
          Mar 28, 2024 16:24:59.452137947 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:25:00.576889038 CET44349704104.98.116.138192.168.2.7
          Mar 28, 2024 16:25:00.577565908 CET49704443192.168.2.7104.98.116.138
          Mar 28, 2024 16:25:01.661406040 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:01.661442995 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:01.661598921 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:01.663610935 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:01.663621902 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.028983116 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.029069901 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.034380913 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.034401894 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.034703016 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.076354027 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.145626068 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.192234993 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.400780916 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.400876999 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.400938988 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.401189089 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.401204109 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.401242971 CET49716443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.401248932 CET4434971623.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.465151072 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.465181112 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.465476036 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.465804100 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.465822935 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.824140072 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.824235916 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.825947046 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.825956106 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.826231003 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:02.827814102 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:02.868242025 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:03.173228025 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:03.173299074 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:03.173388958 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:03.174148083 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:03.174148083 CET49717443192.168.2.723.221.242.90
          Mar 28, 2024 16:25:03.174170017 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:03.174180984 CET4434971723.221.242.90192.168.2.7
          Mar 28, 2024 16:25:03.857661009 CET49671443192.168.2.7204.79.197.203
          Mar 28, 2024 16:25:05.405108929 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:25:08.218848944 CET8049710212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.218866110 CET8049710212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.218933105 CET4971080192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:08.361640930 CET8049712212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.361656904 CET8049712212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.361752033 CET4971280192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:08.496989012 CET8049711212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.497042894 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:08.563014984 CET4971180192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:08.740125895 CET8049711212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:08.836328030 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:08.836390972 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:08.836461067 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:10.577702045 CET49714443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:10.577733040 CET44349714172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:17.311131001 CET49677443192.168.2.720.50.201.200
          Mar 28, 2024 16:25:53.233141899 CET4971080192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:53.373759985 CET4971280192.168.2.7212.49.145.8
          Mar 28, 2024 16:25:53.419281006 CET8049710212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:53.559844971 CET8049712212.49.145.8192.168.2.7
          Mar 28, 2024 16:25:58.593346119 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:58.593378067 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.593574047 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:58.593734980 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:58.593745947 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.800971031 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.801459074 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:58.801479101 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.801873922 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.802642107 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:25:58.802743912 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:25:58.858285904 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:26:08.801748037 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:26:08.801820993 CET44349727172.253.122.103192.168.2.7
          Mar 28, 2024 16:26:08.801870108 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:26:09.744911909 CET49727443192.168.2.7172.253.122.103
          Mar 28, 2024 16:26:09.744942904 CET44349727172.253.122.103192.168.2.7
          TimestampSource PortDest PortSource IPDest IP
          Mar 28, 2024 16:24:56.489501953 CET53572841.1.1.1192.168.2.7
          Mar 28, 2024 16:24:56.520200014 CET53653081.1.1.1192.168.2.7
          Mar 28, 2024 16:24:57.259576082 CET53567791.1.1.1192.168.2.7
          Mar 28, 2024 16:24:57.718398094 CET6008953192.168.2.71.1.1.1
          Mar 28, 2024 16:24:57.718548059 CET5242753192.168.2.71.1.1.1
          Mar 28, 2024 16:24:57.814362049 CET53600891.1.1.1192.168.2.7
          Mar 28, 2024 16:24:57.912646055 CET53524271.1.1.1192.168.2.7
          Mar 28, 2024 16:24:58.530587912 CET6158553192.168.2.71.1.1.1
          Mar 28, 2024 16:24:58.530817032 CET6156553192.168.2.71.1.1.1
          Mar 28, 2024 16:24:58.625422955 CET53615851.1.1.1192.168.2.7
          Mar 28, 2024 16:24:58.625699997 CET53615651.1.1.1192.168.2.7
          Mar 28, 2024 16:24:59.695593119 CET123123192.168.2.7168.61.215.74
          Mar 28, 2024 16:24:59.824615002 CET123123168.61.215.74192.168.2.7
          Mar 28, 2024 16:25:14.254354000 CET53610721.1.1.1192.168.2.7
          Mar 28, 2024 16:25:33.300652981 CET53516181.1.1.1192.168.2.7
          Mar 28, 2024 16:25:53.831049919 CET138138192.168.2.7192.168.2.255
          Mar 28, 2024 16:25:55.995563984 CET53584011.1.1.1192.168.2.7
          Mar 28, 2024 16:25:56.303096056 CET53492591.1.1.1192.168.2.7
          TimestampSource IPDest IPChecksumCodeType
          Mar 28, 2024 16:24:57.912733078 CET192.168.2.71.1.1.1c233(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 28, 2024 16:24:57.718398094 CET192.168.2.71.1.1.10xda6dStandard query (0)repository.edicomnet.comA (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:57.718548059 CET192.168.2.71.1.1.10x744bStandard query (0)repository.edicomnet.com65IN (0x0001)false
          Mar 28, 2024 16:24:58.530587912 CET192.168.2.71.1.1.10x221bStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.530817032 CET192.168.2.71.1.1.10x9731Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 28, 2024 16:24:57.814362049 CET1.1.1.1192.168.2.70xda6dNo error (0)repository.edicomnet.com212.49.145.8A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.103A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.104A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.147A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.106A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.99A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625422955 CET1.1.1.1192.168.2.70x221bNo error (0)www.google.com172.253.122.105A (IP address)IN (0x0001)false
          Mar 28, 2024 16:24:58.625699997 CET1.1.1.1192.168.2.70x9731No error (0)www.google.com65IN (0x0001)false
          Mar 28, 2024 16:25:10.430198908 CET1.1.1.1192.168.2.70xf388No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Mar 28, 2024 16:25:10.430198908 CET1.1.1.1192.168.2.70xf388No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • fs.microsoft.com
          • repository.edicomnet.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.749711212.49.145.8806776C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 16:24:58.022876978 CET439OUTGET / HTTP/1.1
          Host: repository.edicomnet.com
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Mar 28, 2024 16:24:58.205419064 CET562INHTTP/1.1 403 Forbidden
          date: Thu, 28 Mar 2024 15:24:58 GMT
          server: Apache
          x-frame-options: SAMEORIGIN
          strict-transport-security: max-age=600; includeSubdomains;preload
          content-length: 321
          content-type: text/html; charset=iso-8859-1
          Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 2f 0a 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access /on this server.</p><p>Additionally, a 403 Forbiddenerror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
          Mar 28, 2024 16:24:58.314645052 CET392OUTGET /favicon.ico HTTP/1.1
          Host: repository.edicomnet.com
          Connection: keep-alive
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Referer: http://repository.edicomnet.com/
          Accept-Encoding: gzip, deflate
          Accept-Language: en-US,en;q=0.9
          Mar 28, 2024 16:24:58.496010065 CET569INHTTP/1.1 404 Not Found
          date: Thu, 28 Mar 2024 15:24:58 GMT
          server: Apache
          x-frame-options: SAMEORIGIN
          strict-transport-security: max-age=600; includeSubdomains;preload
          content-length: 328
          content-type: text/html; charset=iso-8859-1
          Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /favicon.ico was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.749710212.49.145.8806776C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 16:25:08.218848944 CET233INHTTP/1.1 408 Request Time-out
          Content-length: 110
          Cache-Control: no-cache
          Connection: close
          Content-Type: text/html
          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
          Mar 28, 2024 16:25:53.233141899 CET6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.749712212.49.145.8806776C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Mar 28, 2024 16:25:08.361640930 CET233INHTTP/1.1 408 Request Time-out
          Content-length: 110
          Cache-Control: no-cache
          Connection: close
          Content-Type: text/html
          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
          Mar 28, 2024 16:25:53.373759985 CET6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.74971623.221.242.90443
          TimestampBytes transferredDirectionData
          2024-03-28 15:25:02 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 15:25:02 UTC468INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (chd/073D)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus2-z1
          Cache-Control: public, max-age=229107
          Date: Thu, 28 Mar 2024 15:25:02 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.74971723.221.242.90443
          TimestampBytes transferredDirectionData
          2024-03-28 15:25:02 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-03-28 15:25:03 UTC774INHTTP/1.1 200 OK
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          X-CID: 7
          X-CCC: US
          X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
          X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
          Content-Type: application/octet-stream
          X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
          Cache-Control: public, max-age=229086
          Date: Thu, 28 Mar 2024 15:25:03 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-03-28 15:25:03 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:16:24:49
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff6c4390000
          File size:3'242'272 bytes
          MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:16:24:52
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2332,i,7333287129093996952,18099021527419356767,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff6c4390000
          File size:3'242'272 bytes
          MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:10
          Start time:16:24:56
          Start date:28/03/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://repository.edicomnet.com"
          Imagebase:0x7ff6c4390000
          File size:3'242'272 bytes
          MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly