Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvV

Overview

General Information

Sample URL:https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoeh
Analysis ID:1417166
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 6348 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2296,i,13260245651191188422,802066238751520042,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://id.sysol.me/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49726 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49726 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ HTTP/1.1Host: u7351105.ct.sendgrid.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: id.sysol.meConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: id.sysol.meConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://id.sysol.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6q74vindefmc7f4vheh9q9gef3
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: u7351105.ct.sendgrid.net
Source: unknownHTTP traffic detected: POST /report/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 415Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 16:49:47 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closecache-control: private, no-cache, max-age=0pragma: no-cachevary: Accept-EncodingCF-Cache-Status: BYPASSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 86b91d8f7e123b80-IADalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.5:49719 version: TLS 1.2
Source: classification engineClassification label: clean1.win@17/8@8/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2296,i,13260245651191188422,802066238751520042,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2296,i,13260245651191188422,802066238751520042,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://id.sysol.me/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
id.sysol.me
172.67.173.164
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      www.google.com
      142.251.167.103
      truefalse
        high
        u7351105.ct.sendgrid.net
        167.89.115.54
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            windowsupdatebg.s.llnwi.net
            69.164.0.128
            truefalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://a.nel.cloudflare.com/report/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3Dfalse
                high
                https://id.sysol.me/favicon.icofalse
                • Avira URL Cloud: safe
                unknown
                https://id.sysol.me/false
                  unknown
                  https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.251.167.103
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    35.190.80.1
                    a.nel.cloudflare.comUnited States
                    15169GOOGLEUSfalse
                    167.89.115.54
                    u7351105.ct.sendgrid.netUnited States
                    11377SENDGRIDUSfalse
                    172.67.173.164
                    id.sysol.meUnited States
                    13335CLOUDFLARENETUSfalse
                    IP
                    192.168.2.5
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1417166
                    Start date and time:2024-03-28 17:48:53 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 5s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean1.win@17/8@8/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 172.253.115.102, 172.253.115.101, 172.253.115.113, 172.253.115.139, 172.253.115.100, 172.253.115.138, 142.251.111.94, 172.253.115.84, 34.104.35.123, 20.12.23.50, 23.207.202.72, 69.164.0.128, 192.229.211.108, 52.165.164.15, 172.253.122.94, 72.21.81.240
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, update.googleapis.com, hlb.apr-52dd2-0.edgecastdns.net, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 15:49:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2677
                    Entropy (8bit):3.976064474640915
                    Encrypted:false
                    SSDEEP:48:8dWd1TdhOHwidAKZdA19ehwiZUklqehqy+3:8OTxFy
                    MD5:4B1E4B9FC2D82B1795A81F78BB32315B
                    SHA1:1C55815BAD0AC8BCBA6443DCA20045C3A0EF8F20
                    SHA-256:9382F44C51CDC66ED91C13FCF896562A5FE83D0CE13FD7328C8771929E4B3F13
                    SHA-512:D65AF180DCE857FF548709ACB186F65C70646BCC6694C33ADF9196762E4F0AA166BEF326C2598897D2260E4D13E4E327B2E97590599E7AEA5A3052331E250537
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,....Wt../...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X7............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 15:49:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2679
                    Entropy (8bit):3.9955099475661435
                    Encrypted:false
                    SSDEEP:48:8pd1TdhOHwidAKZdA1weh/iZUkAQkqeh1y+2:8pTD9QYy
                    MD5:46CA308C1650327447F72238CE8C975F
                    SHA1:FDBFCE7851743F28FC61187246C3D8241779BF30
                    SHA-256:1407919A4D726E279E5ADB4119350A173D467028E612A814EA576584BDC1384D
                    SHA-512:5AED2C045E153425AEA849B1894193D85CBAEEAF7FA4939303333B089FA17EEF3223C5961F097E3569C6074FCB38BDB7A45D644F2EFC926D630FA882C438D279
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......./...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X7............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2693
                    Entropy (8bit):4.005841525417129
                    Encrypted:false
                    SSDEEP:48:8xid1TdhsHwidAKZdA14tseh7sFiZUkmgqeh7s7y+BX:8xMTtnBy
                    MD5:A33AB6E3DD3DE999E22E640CFB9B0606
                    SHA1:F45758962046BF1CDF92C65513BAD2A8A5AE92F3
                    SHA-256:554FCDF261D09E1904F0280918F98A5719035A124634A30234613E2B79F57FD8
                    SHA-512:E23258646FECE8D508F56B3A1D1183551DC82487487E2001DE3BFD002A4ACF0095F73936683141619868A050C0499605778CC5866FBC6F25D52981B86A198EE8
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 15:49:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.993034284526442
                    Encrypted:false
                    SSDEEP:48:8Hud1TdhOHwidAKZdA1vehDiZUkwqehJy+R:8HgTgjy
                    MD5:F8A835396B6E5E26059213D7C83B4D44
                    SHA1:B1B498054BBE4A6F93D99E72D2F3FBB877422434
                    SHA-256:95548B226C970C1A952D39385C34F7BB9BA6873F8AC06876955FB65E5BC0D947
                    SHA-512:FB489D6296152EF307D2CBE9E81245AF1E206ECEE0287D4D2CC36FD5A059243BD9D4B06F6DE9CAFC506B322AC801E2B6734241968D3FF3D087C44BCDD48E5FCB
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,..../.../...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X7............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 15:49:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2681
                    Entropy (8bit):3.982001242630573
                    Encrypted:false
                    SSDEEP:48:8H7d1TdhOHwidAKZdA1hehBiZUk1W1qehHy+C:8HfTA9ny
                    MD5:122B2D239DF2E55DF135382D26057A1E
                    SHA1:F03490BCBA1C30DDA74B862CFA7C19F28C4C6C53
                    SHA-256:A968838B6C119FED53FC5C766A0CE41F3D57B98EC6110C5685D004A6C3168A49
                    SHA-512:6CD9C4812170D67747C6C75CDE6E326056646B369DD093F27DE3059ED9BA82901C05A240125337811F24E2C0361EED9068DB9390715A91F173B67DE5366B7F0E
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......./...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X7............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 15:49:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Category:dropped
                    Size (bytes):2683
                    Entropy (8bit):3.994201860895506
                    Encrypted:false
                    SSDEEP:48:8wd1TdhOHwidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbBy+yT+:8OTOT/TbxWOvTbBy7T
                    MD5:2A19884D827873115CAB1DB9EF0D1AEB
                    SHA1:21E85E36A3BCDF8ABC0A0836E31BB9255FBB51B4
                    SHA-256:8618987427E79F40DCB5AAEBD321A7FBA719694756CDD582FEC4A96A495DA83E
                    SHA-512:C3BD827DFF91FB93767494584AF3F5C87E427833DB5F2DE982A82D485867B54FA3CE5CFA24668BEE59EC67545F2145BDBFFFB35C01A35A8CC56B554663E8677D
                    Malicious:false
                    Reputation:low
                    Preview:L..................F.@.. ...$+.,......./...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I|X4.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V|X4.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V|X4.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V|X4............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V|X7............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........+.1n.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with CRLF, LF line terminators
                    Category:downloaded
                    Size (bytes):1249
                    Entropy (8bit):5.242453121762845
                    Encrypted:false
                    SSDEEP:24:hYYIzD6yJRA3ZsjNQCRtgoLY95Mu56+eDHHLFCOXAkRcfRrzd0Ll72rKQk:rq6Kj2CZLY5Mc6NDLYzkYKLlOM
                    MD5:F58515DFE987F7E027C8A71BBC884621
                    SHA1:BEC6AEBF5940EA88FBBFF5748D539453D49FA284
                    SHA-256:679E7E62B81267C93D0778083AE0FD0EFE24172FF0AC581835B54165B3D9ED43
                    SHA-512:F085346A38318F7935D76909DB0367862924CC9B0D96256F7FF4E8999C041E610BBCDE8CA56C92673BDE0991C85E9C9D9B6726ABD91D0C3177462C80D4A99140
                    Malicious:false
                    Reputation:low
                    URL:https://id.sysol.me/favicon.ico
                    Preview:<!DOCTYPE html>.<html style="height:100%">.<head>.<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">.<title> 404 Not Found..</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</style></head>.<body style="color: #444; margin:0;font: normal 14px/20px Arial, Helvetica, sans-serif; height:100%; background-color: #fff;">.<div style="height:auto; min-height:100%; "> <div style="text-align: center; width:800px; margin-left: -400px; position:absolute; top: 30%; left:50%;">. <h1 style="margin:0; font-size:150px; line-height:150px; font-weight:bold;">404</h1>.<h2 style="margin-top:20px;font-size: 30px;">Not Found..</h2>.<p>The resource requested could not be found on this server!</p>.</div></div><div style="color:#f0f0f0; font-size:12px;margin:auto;padding:0px 30px 0px 30px;position:relative;clear:both;height:100px;margin-top:-101px;background-color:#474747;border-top: 1px solid rgba(0,0,0,0.15);box-shadow: 0 1px
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Mar 28, 2024 17:49:39.399087906 CET49675443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:39.401884079 CET49674443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:39.495625019 CET49673443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:45.224019051 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224059105 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.224136114 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224308014 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224337101 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.224452019 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224493027 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224508047 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.224777937 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.224791050 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.566018105 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.566102982 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.567930937 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.567945004 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.568033934 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.568059921 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.569156885 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.569175005 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.569211960 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.569263935 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.570991039 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.571059942 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.571218014 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.571227074 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.571317911 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.571383953 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.619173050 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.619178057 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.619183064 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.666589022 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.800641060 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.800740957 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.800793886 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.801275969 CET49709443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:49:45.801295042 CET44349709167.89.115.54192.168.2.5
                    Mar 28, 2024 17:49:45.911633015 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:45.911652088 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:45.911706924 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:45.912158012 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:45.912169933 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.118535042 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.118788958 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.118808031 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.119869947 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.119941950 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.123259068 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.123326063 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.123434067 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.123441935 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.164427042 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.727293015 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727338076 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727369070 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727385998 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.727397919 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727436066 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.727442980 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727494001 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:46.727535009 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.733259916 CET49713443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:46.733269930 CET44349713172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.051640987 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.051680088 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.051755905 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.052589893 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.052606106 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.252566099 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.253253937 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.253273964 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.253640890 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.254612923 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.254684925 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.255393982 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.300244093 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.316133976 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.316174984 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.316247940 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.316704988 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.316728115 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.595951080 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.596287966 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.596314907 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.597322941 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.597399950 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.681525946 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.681647062 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.681713104 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.703888893 CET49714443192.168.2.5172.67.173.164
                    Mar 28, 2024 17:49:47.703927040 CET44349714172.67.173.164192.168.2.5
                    Mar 28, 2024 17:49:47.845212936 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.845371962 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.885015965 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:47.885052919 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:47.885138035 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:47.887629032 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:47.887645006 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:47.889859915 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.889868975 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:47.931173086 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:47.945030928 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:47.945066929 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:47.947169065 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:47.950968027 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:47.950990915 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.160614014 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.190026999 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.190056086 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.190960884 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.191046000 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.197510004 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.197583914 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.199563980 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.244246006 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.244292021 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.244313002 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.255621910 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.255840063 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.265072107 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.265081882 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.265311956 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.290608883 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.307004929 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.389836073 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.389908075 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.390017033 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.397953987 CET49717443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.397958040 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.397969007 CET4434971735.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.397980928 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.399339914 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.399653912 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.399677038 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.419007063 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.464238882 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.606364965 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.624793053 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.624908924 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.627099037 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.638243914 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.638262987 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.638586044 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.683003902 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.722990036 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.722990036 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.723006964 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.723170042 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.724061966 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.724061966 CET49716443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.724087000 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.724097013 CET4434971623.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.774872065 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.881002903 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.881050110 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.881120920 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.882390976 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:48.882404089 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:48.951545000 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.951613903 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:48.951669931 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.952126026 CET49718443192.168.2.535.190.80.1
                    Mar 28, 2024 17:49:48.952136040 CET4434971835.190.80.1192.168.2.5
                    Mar 28, 2024 17:49:49.009243965 CET49674443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:49.009259939 CET49675443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:49.103018999 CET49673443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:49.232642889 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.232727051 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:49.234332085 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:49.234344006 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.234550953 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.236020088 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:49.280242920 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.576355934 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.576421976 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:49.576478958 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:49.579521894 CET49719443192.168.2.523.221.242.90
                    Mar 28, 2024 17:49:49.579547882 CET4434971923.221.242.90192.168.2.5
                    Mar 28, 2024 17:49:50.494749069 CET4434970323.1.237.91192.168.2.5
                    Mar 28, 2024 17:49:50.495121002 CET49703443192.168.2.523.1.237.91
                    Mar 28, 2024 17:49:57.599941969 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:57.600009918 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:49:57.600179911 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:57.787446022 CET49715443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:49:57.787483931 CET44349715142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:01.199111938 CET49703443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.199331999 CET49703443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.199690104 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.199723005 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.199790955 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.200171947 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.200184107 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.359992027 CET4434970323.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.360207081 CET4434970323.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.528989077 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.529073954 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.790222883 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.790256977 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.790615082 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.790702105 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.828659058 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.828738928 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:01.828849077 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:01.828860044 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:02.200295925 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:02.200376987 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:02.200896025 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:02.200947046 CET4434972623.1.237.91192.168.2.5
                    Mar 28, 2024 17:50:02.200993061 CET49726443192.168.2.523.1.237.91
                    Mar 28, 2024 17:50:30.632234097 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:50:30.632251978 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:50:45.439404011 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:50:45.439481974 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:50:45.439534903 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:50:45.527961016 CET49710443192.168.2.5167.89.115.54
                    Mar 28, 2024 17:50:45.527982950 CET44349710167.89.115.54192.168.2.5
                    Mar 28, 2024 17:50:47.277793884 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:47.277842999 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.278356075 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:47.278459072 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:47.278470039 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.542462111 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.542752028 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:47.542767048 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.543101072 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.543543100 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:47.543629885 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:47.588227034 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:57.539803028 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:57.539874077 CET44349730142.251.167.103192.168.2.5
                    Mar 28, 2024 17:50:57.540214062 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:59.859004974 CET49730443192.168.2.5142.251.167.103
                    Mar 28, 2024 17:50:59.859034061 CET44349730142.251.167.103192.168.2.5
                    TimestampSource PortDest PortSource IPDest IP
                    Mar 28, 2024 17:49:43.380748034 CET53599701.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:43.386094093 CET53653961.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:43.997677088 CET53510261.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:45.124475002 CET5121753192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:45.124665976 CET5471153192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:45.222368002 CET53512171.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:45.223457098 CET53547111.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:45.805092096 CET5151053192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:45.805495977 CET5975853192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:45.909934044 CET53515101.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:45.910907984 CET53597581.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:47.217144012 CET5489853192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:47.217717886 CET6207953192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:47.313165903 CET53620791.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:47.313227892 CET53548981.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:47.844583035 CET5272053192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:47.844882965 CET5599153192.168.2.51.1.1.1
                    Mar 28, 2024 17:49:47.939630985 CET53527201.1.1.1192.168.2.5
                    Mar 28, 2024 17:49:47.940076113 CET53559911.1.1.1192.168.2.5
                    Mar 28, 2024 17:50:01.846501112 CET53530521.1.1.1192.168.2.5
                    Mar 28, 2024 17:50:20.873487949 CET53578091.1.1.1192.168.2.5
                    Mar 28, 2024 17:50:42.756669998 CET53492361.1.1.1192.168.2.5
                    Mar 28, 2024 17:50:44.223031044 CET53584571.1.1.1192.168.2.5
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Mar 28, 2024 17:49:45.124475002 CET192.168.2.51.1.1.10x84ddStandard query (0)u7351105.ct.sendgrid.netA (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.124665976 CET192.168.2.51.1.1.10x24f5Standard query (0)u7351105.ct.sendgrid.net65IN (0x0001)false
                    Mar 28, 2024 17:49:45.805092096 CET192.168.2.51.1.1.10x5192Standard query (0)id.sysol.meA (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.805495977 CET192.168.2.51.1.1.10x2002Standard query (0)id.sysol.me65IN (0x0001)false
                    Mar 28, 2024 17:49:47.217144012 CET192.168.2.51.1.1.10x9e02Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.217717886 CET192.168.2.51.1.1.10x9fefStandard query (0)www.google.com65IN (0x0001)false
                    Mar 28, 2024 17:49:47.844583035 CET192.168.2.51.1.1.10xb5deStandard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.844882965 CET192.168.2.51.1.1.10xad94Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.115.54A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.115.147A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.115.121A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.123.16A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.123.122A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.222368002 CET1.1.1.1192.168.2.50x84ddNo error (0)u7351105.ct.sendgrid.net167.89.123.147A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.909934044 CET1.1.1.1192.168.2.50x5192No error (0)id.sysol.me172.67.173.164A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.909934044 CET1.1.1.1192.168.2.50x5192No error (0)id.sysol.me104.21.88.69A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:45.910907984 CET1.1.1.1192.168.2.50x2002No error (0)id.sysol.me65IN (0x0001)false
                    Mar 28, 2024 17:49:47.313165903 CET1.1.1.1192.168.2.50x9fefNo error (0)www.google.com65IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.103A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.104A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.106A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.105A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.99A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.313227892 CET1.1.1.1192.168.2.50x9e02No error (0)www.google.com142.251.167.147A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:49:47.939630985 CET1.1.1.1192.168.2.50xb5deNo error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:00.537656069 CET1.1.1.1192.168.2.50x8d4aNo error (0)windowsupdatebg.s.llnwi.net69.164.0.128A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:00.537656069 CET1.1.1.1192.168.2.50x8d4aNo error (0)windowsupdatebg.s.llnwi.net69.164.0.0A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:00.745829105 CET1.1.1.1192.168.2.50xec01No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Mar 28, 2024 17:50:00.745829105 CET1.1.1.1192.168.2.50xec01No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:13.840210915 CET1.1.1.1192.168.2.50x46b4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Mar 28, 2024 17:50:13.840210915 CET1.1.1.1192.168.2.50x46b4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:35.969275951 CET1.1.1.1192.168.2.50xfddcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Mar 28, 2024 17:50:35.969275951 CET1.1.1.1192.168.2.50xfddcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Mar 28, 2024 17:50:55.574615955 CET1.1.1.1192.168.2.50xccacNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Mar 28, 2024 17:50:55.574615955 CET1.1.1.1192.168.2.50xccacNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • u7351105.ct.sendgrid.net
                    • id.sysol.me
                    • https:
                      • www.bing.com
                    • a.nel.cloudflare.com
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.549709167.89.115.544433440C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:45 UTC1144OUTGET /ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ HTTP/1.1
                    Host: u7351105.ct.sendgrid.net
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-03-28 16:49:45 UTC218INHTTP/1.1 302 Found
                    Server: nginx
                    Date: Thu, 28 Mar 2024 16:49:45 GMT
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 43
                    Connection: close
                    Location: https://id.sysol.me/
                    X-Robots-Tag: noindex, nofollow
                    2024-03-28 16:49:45 UTC43INData Raw: 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 69 64 2e 73 79 73 6f 6c 2e 6d 65 2f 22 3e 46 6f 75 6e 64 3c 2f 61 3e 2e 0a 0a
                    Data Ascii: <a href="https://id.sysol.me/">Found</a>.


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.549713172.67.173.1644433440C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:46 UTC654OUTGET / HTTP/1.1
                    Host: id.sysol.me
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-03-28 16:49:46 UTC767INHTTP/1.1 200 OK
                    Date: Thu, 28 Mar 2024 16:49:46 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: close
                    set-cookie: PHPSESSID=6q74vindefmc7f4vheh9q9gef3; path=/
                    expires: Thu, 19 Nov 1981 08:52:00 GMT
                    cache-control: no-store, no-cache, must-revalidate
                    pragma: no-cache
                    vary: Accept-Encoding
                    CF-Cache-Status: DYNAMIC
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=EYGNW%2B3J9x63kIJ%2FyEPtaRvA7sJQrXtkT1OqgrIM82d9fsXQnr21kHEQ3ZNi25ry4TP3H9z1Wz%2F1h1ZSdweZW7%2B0xlggVYx%2B6Z7j0rCVBTfNn3SShMhOozcwQzdCXw%3D%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 86b91d885977399e-IAD
                    alt-svc: h3=":443"; ma=86400
                    2024-03-28 16:49:46 UTC602INData Raw: 66 34 66 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 77 69 73 73 20 54 72 61 69 6e 20 53 63 68 65 64 75 6c 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 62 6f 64 79 2c 20 68 74 6d 6c 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20
                    Data Ascii: f4f<!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Swiss Train Schedule</title> <style> body, html { margin: 0;
                    2024-03-28 16:49:46 UTC1369INData Raw: 65 63 74 2c 20 2e 73 63 68 65 64 75 6c 65 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 32 30 70 78 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 68 31 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 64 31 30 30 30 30 3b 20 2f 2a 20 43 68 61 6e 67 65 64 20 74 6f 20 72 65 64 20 2a 2f 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 73 65 6c 65 63 74 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 77 69 64 74 68 3a 20 63 61 6c 63 28 31 30 30 25 20 2d 20 34 30 70 78 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 3a 20 32 70 78 20 73 6f 6c 69 64 20 23 64 31 30 30 30 30 3b 20 2f 2a 20 42 6f 72 64 65 72
                    Data Ascii: ect, .schedule { margin: 20px; } h1 { color: #d10000; /* Changed to red */ } select { width: calc(100% - 40px); padding: 10px; border: 2px solid #d10000; /* Border
                    2024-03-28 16:49:46 UTC1369INData Raw: 20 20 20 20 20 20 3c 74 68 3e 44 65 70 61 72 74 75 72 65 20 54 69 6d 65 3c 2f 74 68 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 68 3e 44 65 73 74 69 6e 61 74 69 6f 6e 3c 2f 74 68 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 68 3e 50 6c 61 74 66 6f 72 6d 3c 2f 74 68 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 68 3e 53 74 61 74 75 73 3c 2f 74 68 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 74 72 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 74 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 62 6f 64 79 20 69 64 3d 22 74 72 61 69 6e 53 63 68 65 64 75 6c 65 22 3e 0a 20 20 20 20
                    Data Ascii: <th>Departure Time</th> <th>Destination</th> <th>Platform</th> <th>Status</th> </tr> </thead> <tbody id="trainSchedule">
                    2024-03-28 16:49:46 UTC586INData Raw: 20 20 20 20 20 20 20 20 20 63 6f 6e 73 74 20 68 6f 75 72 20 3d 20 4d 61 74 68 2e 66 6c 6f 6f 72 28 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 20 2a 20 32 34 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6e 73 74 20 6d 69 6e 75 74 65 20 3d 20 4d 61 74 68 2e 66 6c 6f 6f 72 28 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 20 2a 20 36 30 29 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 72 65 74 75 72 6e 20 60 24 7b 68 6f 75 72 2e 74 6f 53 74 72 69 6e 67 28 29 2e 70 61 64 53 74 61 72 74 28 32 2c 20 27 30 27 29 7d 3a 24 7b 6d 69 6e 75 74 65 2e 74 6f 53 74 72 69 6e 67 28 29 2e 70 61 64 53 74 61 72 74 28 32 2c 20 27 30 27 29 7d 60 3b 0a 20 20 20 20 20 20 20 20 7d 0a 0a 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 63 69
                    Data Ascii: const hour = Math.floor(Math.random() * 24); const minute = Math.floor(Math.random() * 60); return `${hour.toString().padStart(2, '0')}:${minute.toString().padStart(2, '0')}`; } document.getElementById('ci
                    2024-03-28 16:49:46 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.549714172.67.173.1644433440C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:47 UTC624OUTGET /favicon.ico HTTP/1.1
                    Host: id.sysol.me
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://id.sysol.me/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: PHPSESSID=6q74vindefmc7f4vheh9q9gef3
                    2024-03-28 16:49:47 UTC651INHTTP/1.1 404 Not Found
                    Date: Thu, 28 Mar 2024 16:49:47 GMT
                    Content-Type: text/html
                    Transfer-Encoding: chunked
                    Connection: close
                    cache-control: private, no-cache, max-age=0
                    pragma: no-cache
                    vary: Accept-Encoding
                    CF-Cache-Status: BYPASS
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 86b91d8f7e123b80-IAD
                    alt-svc: h3=":443"; ma=86400
                    2024-03-28 16:49:47 UTC718INData Raw: 34 65 31 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f
                    Data Ascii: 4e1<!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no"><title> 404 Not Found</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</
                    2024-03-28 16:49:47 UTC538INData Raw: 75 72 63 65 20 72 65 71 75 65 73 74 65 64 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 21 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 64 69 76 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 23 66 30 66 30 66 30 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 6d 61 72 67 69 6e 3a 61 75 74 6f 3b 70 61 64 64 69 6e 67 3a 30 70 78 20 33 30 70 78 20 30 70 78 20 33 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 63 6c 65 61 72 3a 62 6f 74 68 3b 68 65 69 67 68 74 3a 31 30 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 31 30 31 70 78 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 34 37 34 37 34 37 3b 62 6f 72 64 65 72 2d 74 6f 70 3a 20 31 70 78 20 73 6f 6c 69 64 20 72 67
                    Data Ascii: urce requested could not be found on this server!</p></div></div><div style="color:#f0f0f0; font-size:12px;margin:auto;padding:0px 30px 0px 30px;position:relative;clear:both;height:100px;margin-top:-101px;background-color:#474747;border-top: 1px solid rg
                    2024-03-28 16:49:47 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.54971735.190.80.14433440C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:48 UTC532OUTOPTIONS /report/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3D HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Origin: https://id.sysol.me
                    Access-Control-Request-Method: POST
                    Access-Control-Request-Headers: content-type
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-03-28 16:49:48 UTC336INHTTP/1.1 200 OK
                    Content-Length: 0
                    access-control-max-age: 86400
                    access-control-allow-methods: POST, OPTIONS
                    access-control-allow-origin: *
                    access-control-allow-headers: content-length, content-type
                    date: Thu, 28 Mar 2024 16:49:48 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.54971623.221.242.90443
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:48 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-03-28 16:49:48 UTC468INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/073D)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus2-z1
                    Cache-Control: public, max-age=224021
                    Date: Thu, 28 Mar 2024 16:49:48 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.54971835.190.80.14433440C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:48 UTC478OUTPOST /report/v4?s=iXAsFW2sOHRlDs5HvVSfM1QcR58I%2FEAclgjlMZW%2BqF%2BrMEncLHORJ5Xcc20yV5jk2atk78edGexumU2rSthLFGoniehmGpHF7wo5b%2FhmbeloIyJyncBlvQtR1Jlmxg%3D%3D HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Content-Length: 415
                    Content-Type: application/reports+json
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-03-28 16:49:48 UTC415OUTData Raw: 5b 7b 22 61 67 65 22 3a 31 35 35 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 36 34 37 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 69 64 2e 73 79 73 6f 6c 2e 6d 65 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 37 33 2e 31 36 34 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68
                    Data Ascii: [{"age":155,"body":{"elapsed_time":647,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://id.sysol.me/","sampling_fraction":1.0,"server_ip":"172.67.173.164","status_code":404,"type":"http.error"},"type":"network-error","url":"h
                    2024-03-28 16:49:48 UTC168INHTTP/1.1 200 OK
                    Content-Length: 0
                    date: Thu, 28 Mar 2024 16:49:48 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    6192.168.2.54971923.221.242.90443
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:49:49 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-03-28 16:49:49 UTC774INHTTP/1.1 200 OK
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-CID: 7
                    X-CCC: US
                    X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
                    X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
                    Content-Type: application/octet-stream
                    X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=224000
                    Date: Thu, 28 Mar 2024 16:49:49 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-03-28 16:49:49 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination Port
                    7192.168.2.54972623.1.237.91443
                    TimestampBytes transferredDirectionData
                    2024-03-28 16:50:01 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
                    Origin: https://www.bing.com
                    Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                    Accept: */*
                    Accept-Language: en-CH
                    Content-type: text/xml
                    X-Agent-DeviceId: 01000A410900D492
                    X-BM-CBT: 1696428841
                    X-BM-DateFormat: dd/MM/yyyy
                    X-BM-DeviceDimensions: 784x984
                    X-BM-DeviceDimensionsLogical: 784x984
                    X-BM-DeviceScale: 100
                    X-BM-DTZ: 120
                    X-BM-Market: CH
                    X-BM-Theme: 000000;0078d7
                    X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                    X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
                    X-Device-isOptin: false
                    X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                    X-Device-OSSKU: 48
                    X-Device-Touch: false
                    X-DeviceID: 01000A410900D492
                    X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
                    X-MSEdge-ExternalExpType: JointCoord
                    X-PositionerType: Desktop
                    X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                    X-Search-CortanaAvailableCapabilities: None
                    X-Search-SafeSearch: Moderate
                    X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
                    X-UserAgeClass: Unknown
                    Accept-Encoding: gzip, deflate, br
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                    Host: www.bing.com
                    Content-Length: 2484
                    Connection: Keep-Alive
                    Cache-Control: no-cache
                    Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1711644568913&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
                    2024-03-28 16:50:01 UTC1OUTData Raw: 3c
                    Data Ascii: <
                    2024-03-28 16:50:01 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
                    Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
                    2024-03-28 16:50:02 UTC478INHTTP/1.1 204 No Content
                    Access-Control-Allow-Origin: *
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    X-MSEdge-Ref: Ref A: 34025F9477D34C9AB4E7655EDAA3D12D Ref B: LAX311000108019 Ref C: 2024-03-28T16:50:02Z
                    Date: Thu, 28 Mar 2024 16:50:02 GMT
                    Connection: close
                    Alt-Svc: h3=":443"; ma=93600
                    X-CDN-TraceID: 0.57ed0117.1711644601.a1c07b


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:17:49:38
                    Start date:28/03/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:17:49:41
                    Start date:28/03/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2296,i,13260245651191188422,802066238751520042,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:17:49:43
                    Start date:28/03/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u7351105.ct.sendgrid.net/ls/click?upn=u001.8DaV8TKv6VMQvQ9LbKzQli6G-2FB9J-2FPIuyT-2BdXuI7pU4-3D8had_9opN5qBvr7sD8xNv8U61zKsA49LnUSSXLaEoZtTjNF5yNW7KZ5DY6sBQ-2BBcd-2Bih7q4dOuzqV-2FpyiGG42JbUoehpSOTO1DJ7yYxjf3XqB4rSfV0wYAJfkM-2FAw5TRtq4uRxWv-2FtrN0IBVT03AqDUYQw46frYxKYwXFSl96XN2a5xqQ8fs42WgUvVs7qrU4Ybun21xMP2WGriu07DG9XW2tSeHyOVFI6EG8CM2DxNi-2BGGieBRPSVM0KpZCC-2FMw1UrzxshTPShqnxvT8tlzzPv6hZG1cwC9w0xx7TAAjHYtNvjgH9sjQfmVlY0x7p9zXAD7g4ayXS1MIpAnv0QRTc3tBpI6YWXmWN6AsnWusaLz5tA-2FCscOSaPPfrfycclc-2BgjVZ"
                    Imagebase:0x7ff715980000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly