Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb

Overview

General Information

Sample URL:https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb
Analysis ID:1417194
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3592 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5724 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,5588499114242152290,15871520837934263375,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fbHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb HTTP/1.1Host: assets-fra.mkt.dynamics.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: assets-fra.mkt.dynamics.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fbAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: assets-fra.mkt.dynamics.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 17:49:13 GMTContent-Type: text/htmlContent-Length: 548Connection: closeStrict-Transport-Security: max-age=2592000; preloadx-azure-ref: 20240328T174913Z-fbsuskukgd7u74wr9uws7q3kxc00000001h000000000h8k4x-fd-int-roxy-purgeid: 67837719X-Cache: TCP_MISS
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 28 Mar 2024 17:49:14 GMTContent-Type: text/htmlContent-Length: 548Connection: closeStrict-Transport-Security: max-age=2592000; preloadx-azure-ref: 20240328T174913Z-x67sv75c354b335e6u6f3msdew00000001h000000000b0rmx-fd-int-roxy-purgeid: 67837719X-Cache: TCP_MISS
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,5588499114242152290,15871520837934263375,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,5588499114242152290,15871520837934263375,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.16.105
truefalse
    high
    part-0012.t-0009.t-msedge.net
    13.107.246.40
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        windowsupdatebg.s.llnwi.net
        69.164.0.0
        truefalse
          unknown
          assets-fra.mkt.dynamics.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fbfalse
              high
              https://assets-fra.mkt.dynamics.com/favicon.icofalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                13.107.246.40
                part-0012.t-0009.t-msedge.netUnited States
                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.251.16.105
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.16
                192.168.2.4
                192.168.2.5
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1417194
                Start date and time:2024-03-28 18:48:17 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 11s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/4@4/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.253.115.94, 142.251.163.138, 142.251.163.102, 142.251.163.101, 142.251.163.139, 142.251.163.100, 142.251.163.113, 172.253.122.84, 34.104.35.123, 20.114.59.183, 69.164.0.0, 52.165.164.15, 192.229.211.108, 20.166.126.56, 172.253.62.94
                • Excluded domains from analysis (whitelisted): assets-mkt-fra.azureedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, assets-mkt-fra.afd.azureedge.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, azureedge-t-prod.trafficmanager.net, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):548
                Entropy (8bit):4.688532577858027
                Encrypted:false
                SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                MD5:370E16C3B7DBA286CFF055F93B9A94D8
                SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                Malicious:false
                Reputation:low
                URL:https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb
                Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):548
                Entropy (8bit):4.688532577858027
                Encrypted:false
                SSDEEP:12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc
                MD5:370E16C3B7DBA286CFF055F93B9A94D8
                SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                Malicious:false
                Reputation:low
                URL:https://assets-fra.mkt.dynamics.com/favicon.ico
                Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Mar 28, 2024 18:49:03.937371016 CET49675443192.168.2.4173.222.162.32
                Mar 28, 2024 18:49:12.811252117 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.811285019 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:12.811376095 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.815089941 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.815139055 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:12.815231085 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.815330029 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.815342903 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:12.815484047 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:12.815502882 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.158045053 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.158575058 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.158607006 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.159640074 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.159698963 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.161154032 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.161221027 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.161331892 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.161341906 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.172396898 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.173350096 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.173361063 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.174537897 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.174599886 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.175074100 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.175138950 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.210979939 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.226444006 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.226453066 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.272857904 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.552109957 CET49675443192.168.2.4173.222.162.32
                Mar 28, 2024 18:49:13.710746050 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.711159945 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.711240053 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.711730957 CET49735443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.711745977 CET4434973513.107.246.40192.168.2.4
                Mar 28, 2024 18:49:13.765099049 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:13.812237024 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:14.015942097 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.015985966 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.016047955 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.016271114 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.016283989 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.229649067 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.230571032 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.230591059 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.231652021 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.231718063 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.235220909 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.235285044 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.279407024 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.279413939 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:14.313647032 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:14.313967943 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:14.314013958 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:14.322293997 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:14.333112001 CET49736443192.168.2.413.107.246.40
                Mar 28, 2024 18:49:14.333131075 CET4434973613.107.246.40192.168.2.4
                Mar 28, 2024 18:49:15.514981031 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:15.515012980 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:15.515923977 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:15.517400980 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:15.517415047 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.117618084 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.117696047 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.129978895 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.129990101 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.130248070 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.171087980 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.339683056 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.380245924 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.513106108 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.513186932 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.513257980 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.521411896 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.521425009 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.521466017 CET49740443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.521471024 CET4434974023.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.647084951 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.647125959 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:17.647201061 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.647784948 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:17.647808075 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:18.209595919 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:18.209721088 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:18.211173058 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:18.211182117 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:18.211461067 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:18.212910891 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:18.260241985 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:19.364828110 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:19.364890099 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:19.364964962 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:19.391990900 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:19.392005920 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:19.392019033 CET49741443192.168.2.423.221.242.90
                Mar 28, 2024 18:49:19.392024994 CET4434974123.221.242.90192.168.2.4
                Mar 28, 2024 18:49:24.294070959 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:24.294131041 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:24.294244051 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:25.159218073 CET49739443192.168.2.4142.251.16.105
                Mar 28, 2024 18:49:25.159250021 CET44349739142.251.16.105192.168.2.4
                Mar 28, 2024 18:49:28.657198906 CET4972380192.168.2.472.21.81.240
                Mar 28, 2024 18:49:28.751719952 CET804972372.21.81.240192.168.2.4
                Mar 28, 2024 18:49:28.751775026 CET4972380192.168.2.472.21.81.240
                Mar 28, 2024 18:50:13.969459057 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:13.969490051 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:13.969558001 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:13.970139027 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:13.970151901 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:14.197366953 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:14.197781086 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:14.197794914 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:14.198143005 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:14.199146032 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:14.199213982 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:14.248831034 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:18.202090979 CET4972480192.168.2.472.21.81.240
                Mar 28, 2024 18:50:18.297605038 CET804972472.21.81.240192.168.2.4
                Mar 28, 2024 18:50:18.297688961 CET4972480192.168.2.472.21.81.240
                Mar 28, 2024 18:50:24.203785896 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:24.203871012 CET44349749142.251.16.105192.168.2.4
                Mar 28, 2024 18:50:24.203926086 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:25.154405117 CET49749443192.168.2.4142.251.16.105
                Mar 28, 2024 18:50:25.154431105 CET44349749142.251.16.105192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Mar 28, 2024 18:49:10.932322979 CET53572751.1.1.1192.168.2.4
                Mar 28, 2024 18:49:10.963464022 CET53494921.1.1.1192.168.2.4
                Mar 28, 2024 18:49:12.093355894 CET53550671.1.1.1192.168.2.4
                Mar 28, 2024 18:49:12.687377930 CET5181653192.168.2.41.1.1.1
                Mar 28, 2024 18:49:12.687555075 CET5206353192.168.2.41.1.1.1
                Mar 28, 2024 18:49:13.917751074 CET6036253192.168.2.41.1.1.1
                Mar 28, 2024 18:49:13.917934895 CET5168053192.168.2.41.1.1.1
                Mar 28, 2024 18:49:14.013478041 CET53603621.1.1.1192.168.2.4
                Mar 28, 2024 18:49:14.014046907 CET53516801.1.1.1192.168.2.4
                Mar 28, 2024 18:49:29.222527027 CET53640181.1.1.1192.168.2.4
                Mar 28, 2024 18:49:29.786509037 CET138138192.168.2.4192.168.2.255
                Mar 28, 2024 18:49:48.231755972 CET53559261.1.1.1192.168.2.4
                Mar 28, 2024 18:50:10.270864964 CET53581451.1.1.1192.168.2.4
                Mar 28, 2024 18:50:10.827569008 CET53629791.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 28, 2024 18:49:12.687377930 CET192.168.2.41.1.1.10xdc76Standard query (0)assets-fra.mkt.dynamics.comA (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:12.687555075 CET192.168.2.41.1.1.10xd013Standard query (0)assets-fra.mkt.dynamics.com65IN (0x0001)false
                Mar 28, 2024 18:49:13.917751074 CET192.168.2.41.1.1.10x83f8Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:13.917934895 CET192.168.2.41.1.1.10x34e6Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 28, 2024 18:49:12.803174973 CET1.1.1.1192.168.2.40xd013No error (0)assets-fra.mkt.dynamics.comassets-mkt-fra.azureedge.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:49:12.806606054 CET1.1.1.1192.168.2.40xdc76No error (0)assets-fra.mkt.dynamics.comassets-mkt-fra.azureedge.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:49:12.806606054 CET1.1.1.1192.168.2.40xdc76No error (0)shed.dual-low.part-0012.t-0009.t-msedge.netpart-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:49:12.806606054 CET1.1.1.1192.168.2.40xdc76No error (0)part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:12.806606054 CET1.1.1.1192.168.2.40xdc76No error (0)part-0012.t-0009.t-msedge.net13.107.213.40A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.013478041 CET1.1.1.1192.168.2.40x83f8No error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:14.014046907 CET1.1.1.1192.168.2.40x34e6No error (0)www.google.com65IN (0x0001)false
                Mar 28, 2024 18:49:26.957844973 CET1.1.1.1192.168.2.40xea04No error (0)windowsupdatebg.s.llnwi.net69.164.0.0A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:26.957844973 CET1.1.1.1192.168.2.40xea04No error (0)windowsupdatebg.s.llnwi.net69.164.0.128A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:27.871644974 CET1.1.1.1192.168.2.40xf48bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:49:27.871644974 CET1.1.1.1192.168.2.40xf48bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Mar 28, 2024 18:49:44.299951077 CET1.1.1.1192.168.2.40x7d19No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:49:44.299951077 CET1.1.1.1192.168.2.40x7d19No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Mar 28, 2024 18:50:03.361972094 CET1.1.1.1192.168.2.40x9a06No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:50:03.361972094 CET1.1.1.1192.168.2.40x9a06No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Mar 28, 2024 18:50:22.985788107 CET1.1.1.1192.168.2.40x516No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 18:50:22.985788107 CET1.1.1.1192.168.2.40x516No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • assets-fra.mkt.dynamics.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44973513.107.246.404435724C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-03-28 17:49:13 UTC768OUTGET /693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb HTTP/1.1
                Host: assets-fra.mkt.dynamics.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-03-28 17:49:13 UTC313INHTTP/1.1 404 Not Found
                Date: Thu, 28 Mar 2024 17:49:13 GMT
                Content-Type: text/html
                Content-Length: 548
                Connection: close
                Strict-Transport-Security: max-age=2592000; preload
                x-azure-ref: 20240328T174913Z-fbsuskukgd7u74wr9uws7q3kxc00000001h000000000h8k4
                x-fd-int-roxy-purgeid: 67837719
                X-Cache: TCP_MISS
                2024-03-28 17:49:13 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44973613.107.246.404435724C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-03-28 17:49:13 UTC708OUTGET /favicon.ico HTTP/1.1
                Host: assets-fra.mkt.dynamics.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-03-28 17:49:14 UTC313INHTTP/1.1 404 Not Found
                Date: Thu, 28 Mar 2024 17:49:14 GMT
                Content-Type: text/html
                Content-Length: 548
                Connection: close
                Strict-Transport-Security: max-age=2592000; preload
                x-azure-ref: 20240328T174913Z-x67sv75c354b335e6u6f3msdew00000001h000000000b0rm
                x-fd-int-roxy-purgeid: 67837719
                X-Cache: TCP_MISS
                2024-03-28 17:49:14 UTC548INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20
                Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974023.221.242.90443
                TimestampBytes transferredDirectionData
                2024-03-28 17:49:17 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-03-28 17:49:17 UTC468INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus2-z1
                Cache-Control: public, max-age=220452
                Date: Thu, 28 Mar 2024 17:49:17 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974123.221.242.90443
                TimestampBytes transferredDirectionData
                2024-03-28 17:49:18 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-03-28 17:49:19 UTC774INHTTP/1.1 200 OK
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-CID: 7
                X-CCC: US
                X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
                X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
                Content-Type: application/octet-stream
                X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=220431
                Date: Thu, 28 Mar 2024 17:49:18 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-03-28 17:49:19 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:18:49:07
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:18:49:08
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2272,i,5588499114242152290,15871520837934263375,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:18:49:12
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets-fra.mkt.dynamics.com/693cf829reb-ee1148%6045bd6e9afa/digitalassets/standaloneforms/aa7d5e09-b2eb-ee11-a1fd%6045bd6e68fb"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly