Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://usersync.tiqcdn.net

Overview

General Information

Sample URL:http://usersync.tiqcdn.net
Analysis ID:1417312
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6100 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2256,i,15393059275229270124,13609790808308644620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://usersync.tiqcdn.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://usersync.tiqcdn.net/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.50.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.207.202.187
Source: unknownTCP traffic detected without corresponding DNS query: 23.207.202.173
Source: unknownTCP traffic detected without corresponding DNS query: 23.207.202.187
Source: unknownTCP traffic detected without corresponding DNS query: 23.207.202.173
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: usersync.tiqcdn.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: usersync.tiqcdn.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://usersync.tiqcdn.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: usersync.tiqcdn.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: usersync.tiqcdn.net
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.21.2Date: Thu, 28 Mar 2024 22:18:51 GMTContent-Type: text/html; charset=UTF-8Content-Length: 555Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.21.2Date: Thu, 28 Mar 2024 22:18:51 GMTContent-Type: text/html; charset=UTF-8Content-Length: 555Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.199.50.2:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2256,i,15393059275229270124,13609790808308644620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://usersync.tiqcdn.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2256,i,15393059275229270124,13609790808308644620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://usersync.tiqcdn.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://usersync.tiqcdn.net/favicon.ico0%Avira URL Cloudsafe
http://usersync.tiqcdn.net/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
usersync.tiqcdn.net
179.60.147.91
truefalse
    unknown
    www.google.com
    142.251.16.103
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        windowsupdatebg.s.llnwi.net
        69.164.0.128
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://usersync.tiqcdn.net/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://usersync.tiqcdn.net/false
            unknown
            http://usersync.tiqcdn.net/false
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.251.16.103
            www.google.comUnited States
            15169GOOGLEUSfalse
            179.60.147.91
            usersync.tiqcdn.netBelize
            42237ICMESEfalse
            IP
            192.168.2.4
            192.168.2.5
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1417312
            Start date and time:2024-03-28 23:18:00 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 12s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://usersync.tiqcdn.net
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/4@6/5
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.115.94, 142.251.163.113, 142.251.163.101, 142.251.163.102, 142.251.163.139, 142.251.163.100, 142.251.163.138, 142.251.111.84, 34.104.35.123, 13.85.23.86, 69.164.0.128, 192.229.211.108, 13.95.31.18, 142.251.16.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://usersync.tiqcdn.net
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):555
            Entropy (8bit):4.709225644400194
            Encrypted:false
            SSDEEP:12:TvgsoCVIogs01lI5r6K1INGlTF5TF5TF5TF5TF5TFK:cEQtnNs7TPTPTPTPTPTc
            MD5:A7D926BCA93A10F50DA72C1C9F2E6E22
            SHA1:6102F737B92693392146485620D01C2F6C37D2BD
            SHA-256:5DF088462ACD9911DD42359506EB8D3D3A4ACCB84587AE1FFD80BA993FF8CD82
            SHA-512:60207ED0BB5DE6E07B516595605976512703F6559E620DE286F159493B466EA13BEE6AF77F2F1CD3E69AC062289F860822F433333193B27AF597A2A2D24F737B
            Malicious:false
            Reputation:low
            URL:https://usersync.tiqcdn.net/
            Preview:<html>..<head><title>403 Forbidden</title></head>..<body>..<center><h1>403 Forbidden</h1></center>..<hr><center>nginx/1.21.2</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):555
            Entropy (8bit):4.736606584045097
            Encrypted:false
            SSDEEP:12:TjeRHVIdtklI5r6K1INGlTF5TF5TF5TF5TF5TFK:neRH68Ns7TPTPTPTPTPTc
            MD5:A5B6234085A0354ECEC1187BCFF9841D
            SHA1:27315ECA093024D2E195B53B82DD68CAB7C5E910
            SHA-256:E4073CCFB783429CD5E20A1E86E8F608512F4DBD0610E160259C6BADAE4B69D6
            SHA-512:B77E0F60E1D3CBA06CA32E73CCA76BDD120039D9C0EA12CA0553FEDD2EA1712217D373CBEB6EBEEDF6B44961C623305291ED05965F8BBEBB02919C0DCE647554
            Malicious:false
            Reputation:low
            URL:https://usersync.tiqcdn.net/favicon.ico
            Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.21.2</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 28, 2024 23:18:41.920989037 CET49675443192.168.2.4173.222.162.32
            Mar 28, 2024 23:18:42.874003887 CET49678443192.168.2.4104.46.162.224
            Mar 28, 2024 23:18:50.087450027 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.087817907 CET4973680192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.248984098 CET4973780192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.271740913 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.271828890 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.271867037 CET8049736179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.272022963 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.272054911 CET4973680192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.433593988 CET8049737179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.434020996 CET4973780192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.456243038 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.456316948 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.557789087 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.557811975 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.557881117 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.558109999 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.558120012 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.679080963 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.922194958 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.922547102 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.922569036 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.923434973 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.923496962 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.925146103 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.925200939 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.925352097 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:50.925359011 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:50.969630957 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.266654968 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.266715050 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.266769886 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.267669916 CET49738443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.267688990 CET44349738179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.339574099 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.339622021 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.339689970 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.339910984 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.339927912 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.531308889 CET49675443192.168.2.4173.222.162.32
            Mar 28, 2024 23:18:51.705115080 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.705533028 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.705552101 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.705980062 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.706685066 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.706760883 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:51.707051039 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:51.752230883 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:52.056633949 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:52.056699991 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:52.056750059 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:52.059742928 CET49741443192.168.2.4179.60.147.91
            Mar 28, 2024 23:18:52.059756994 CET44349741179.60.147.91192.168.2.4
            Mar 28, 2024 23:18:53.001956940 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.002005100 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.002201080 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.011794090 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.011809111 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.233999014 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.235817909 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.235838890 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.236897945 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.237016916 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.240269899 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.240331888 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.294733047 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.294744015 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:18:53.341595888 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:18:53.457762957 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.457808018 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.457916021 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.460160017 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.460175037 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.671948910 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.672056913 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.675836086 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.675851107 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.676091909 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.732445002 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.743663073 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.788233995 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.868170977 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.868349075 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.868360043 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.868369102 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.868390083 CET49743443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.868417978 CET4434974323.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.909883976 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.909919977 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:53.909996033 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.910346985 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:53.910357952 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.116204023 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.116274118 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:54.117597103 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:54.117604971 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.117842913 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.118994951 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:54.160238981 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.318690062 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.318747997 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:18:54.318799973 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:54.321384907 CET49744443192.168.2.423.199.50.2
            Mar 28, 2024 23:18:54.321399927 CET4434974423.199.50.2192.168.2.4
            Mar 28, 2024 23:19:03.230773926 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:03.230829954 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:03.230921030 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:05.132498980 CET49742443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:05.132531881 CET44349742142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:35.279284954 CET4973680192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:35.435549974 CET4973780192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:35.464325905 CET8049736179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:35.466803074 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:35.619875908 CET8049737179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:35.653511047 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:50.455265045 CET8049736179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:50.455867052 CET4973680192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:50.616647005 CET8049737179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:50.616811037 CET4973780192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:50.986998081 CET4973780192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:50.987000942 CET4973680192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:51.171773911 CET8049736179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:51.171910048 CET8049737179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:52.948203087 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:52.948235035 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:52.952241898 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:52.955413103 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:52.955425024 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:53.161247015 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:53.161695004 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:53.161705017 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:53.162025928 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:53.162594080 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:53.162645102 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:19:53.216960907 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:19:55.456509113 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:19:55.456578970 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:56.984513044 CET4973580192.168.2.4179.60.147.91
            Mar 28, 2024 23:19:57.168860912 CET8049735179.60.147.91192.168.2.4
            Mar 28, 2024 23:20:01.810973883 CET4972380192.168.2.423.207.202.187
            Mar 28, 2024 23:20:01.811407089 CET4972480192.168.2.423.207.202.173
            Mar 28, 2024 23:20:01.905469894 CET804972323.207.202.187192.168.2.4
            Mar 28, 2024 23:20:01.905514956 CET4972380192.168.2.423.207.202.187
            Mar 28, 2024 23:20:01.905776024 CET804972423.207.202.173192.168.2.4
            Mar 28, 2024 23:20:01.905832052 CET4972480192.168.2.423.207.202.173
            Mar 28, 2024 23:20:03.167844057 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:20:03.167903900 CET44349753142.251.16.103192.168.2.4
            Mar 28, 2024 23:20:03.167944908 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:20:04.984934092 CET49753443192.168.2.4142.251.16.103
            Mar 28, 2024 23:20:04.984958887 CET44349753142.251.16.103192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Mar 28, 2024 23:18:48.715399981 CET53594071.1.1.1192.168.2.4
            Mar 28, 2024 23:18:48.809206009 CET53618111.1.1.1192.168.2.4
            Mar 28, 2024 23:18:49.549304962 CET53492571.1.1.1192.168.2.4
            Mar 28, 2024 23:18:49.990552902 CET5699653192.168.2.41.1.1.1
            Mar 28, 2024 23:18:49.990871906 CET5361653192.168.2.41.1.1.1
            Mar 28, 2024 23:18:50.086704016 CET53536161.1.1.1192.168.2.4
            Mar 28, 2024 23:18:50.086724997 CET53569961.1.1.1192.168.2.4
            Mar 28, 2024 23:18:50.460208893 CET6548453192.168.2.41.1.1.1
            Mar 28, 2024 23:18:50.460375071 CET5134453192.168.2.41.1.1.1
            Mar 28, 2024 23:18:50.555449963 CET53654841.1.1.1192.168.2.4
            Mar 28, 2024 23:18:50.557400942 CET53513441.1.1.1192.168.2.4
            Mar 28, 2024 23:18:52.896505117 CET6454953192.168.2.41.1.1.1
            Mar 28, 2024 23:18:52.896935940 CET5665153192.168.2.41.1.1.1
            Mar 28, 2024 23:18:52.992111921 CET53645491.1.1.1192.168.2.4
            Mar 28, 2024 23:18:52.992130995 CET53566511.1.1.1192.168.2.4
            Mar 28, 2024 23:19:07.153016090 CET53592961.1.1.1192.168.2.4
            Mar 28, 2024 23:19:13.396394968 CET138138192.168.2.4192.168.2.255
            Mar 28, 2024 23:19:26.379507065 CET53507071.1.1.1192.168.2.4
            Mar 28, 2024 23:19:48.349102020 CET53586541.1.1.1192.168.2.4
            Mar 28, 2024 23:19:49.314558983 CET53535151.1.1.1192.168.2.4
            Mar 28, 2024 23:20:15.767230988 CET53652381.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 28, 2024 23:18:49.990552902 CET192.168.2.41.1.1.10xbbaeStandard query (0)usersync.tiqcdn.netA (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:49.990871906 CET192.168.2.41.1.1.10xfe0cStandard query (0)usersync.tiqcdn.net65IN (0x0001)false
            Mar 28, 2024 23:18:50.460208893 CET192.168.2.41.1.1.10x2d97Standard query (0)usersync.tiqcdn.netA (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:50.460375071 CET192.168.2.41.1.1.10x1026Standard query (0)usersync.tiqcdn.net65IN (0x0001)false
            Mar 28, 2024 23:18:52.896505117 CET192.168.2.41.1.1.10xe7a2Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.896935940 CET192.168.2.41.1.1.10xabefStandard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 28, 2024 23:18:50.086724997 CET1.1.1.1192.168.2.40xbbaeNo error (0)usersync.tiqcdn.net179.60.147.91A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:50.555449963 CET1.1.1.1192.168.2.40x2d97No error (0)usersync.tiqcdn.net179.60.147.91A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992111921 CET1.1.1.1192.168.2.40xe7a2No error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
            Mar 28, 2024 23:18:52.992130995 CET1.1.1.1192.168.2.40xabefNo error (0)www.google.com65IN (0x0001)false
            Mar 28, 2024 23:19:04.902988911 CET1.1.1.1192.168.2.40xa722No error (0)windowsupdatebg.s.llnwi.net69.164.0.128A (IP address)IN (0x0001)false
            Mar 28, 2024 23:19:05.210028887 CET1.1.1.1192.168.2.40x8baaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 28, 2024 23:19:05.210028887 CET1.1.1.1192.168.2.40x8baaNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 28, 2024 23:19:18.135334015 CET1.1.1.1192.168.2.40xef3aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 28, 2024 23:19:18.135334015 CET1.1.1.1192.168.2.40xef3aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 28, 2024 23:19:41.562263966 CET1.1.1.1192.168.2.40x566dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 28, 2024 23:19:41.562263966 CET1.1.1.1192.168.2.40x566dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 28, 2024 23:20:00.953902960 CET1.1.1.1192.168.2.40xa295No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 28, 2024 23:20:00.953902960 CET1.1.1.1192.168.2.40xa295No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • usersync.tiqcdn.net
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735179.60.147.91805016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 28, 2024 23:18:50.272022963 CET434OUTGET / HTTP/1.1
            Host: usersync.tiqcdn.net
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Mar 28, 2024 23:18:50.456316948 CET376INHTTP/1.1 301 Moved Permanently
            Server: nginx/1.21.2
            Date: Thu, 28 Mar 2024 22:18:50 GMT
            Content-Type: text/html
            Content-Length: 169
            Connection: keep-alive
            Location: https://usersync.tiqcdn.net:443/
            Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 31 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx/1.21.2</center></body></html>
            Mar 28, 2024 23:19:35.466803074 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736179.60.147.91805016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 28, 2024 23:19:35.279284954 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449737179.60.147.91805016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 28, 2024 23:19:35.435549974 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449738179.60.147.914435016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-28 22:18:50 UTC662OUTGET / HTTP/1.1
            Host: usersync.tiqcdn.net
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-28 22:18:51 UTC165INHTTP/1.1 403 Forbidden
            Server: nginx/1.21.2
            Date: Thu, 28 Mar 2024 22:18:51 GMT
            Content-Type: text/html; charset=UTF-8
            Content-Length: 555
            Connection: close
            2024-03-28 22:18:51 UTC555INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 31 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20
            Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx/1.21.2</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449741179.60.147.914435016C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-28 22:18:51 UTC594OUTGET /favicon.ico HTTP/1.1
            Host: usersync.tiqcdn.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://usersync.tiqcdn.net/
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-28 22:18:52 UTC165INHTTP/1.1 404 Not Found
            Server: nginx/1.21.2
            Date: Thu, 28 Mar 2024 22:18:51 GMT
            Content-Type: text/html; charset=UTF-8
            Content-Length: 555
            Connection: close
            2024-03-28 22:18:52 UTC555INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 31 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20
            Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.21.2</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974323.199.50.2443
            TimestampBytes transferredDirectionData
            2024-03-28 22:18:53 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-28 22:18:53 UTC468INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (chd/0790)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus2-z1
            Cache-Control: public, max-age=204237
            Date: Thu, 28 Mar 2024 22:18:53 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974423.199.50.2443
            TimestampBytes transferredDirectionData
            2024-03-28 22:18:54 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-28 22:18:54 UTC660INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-CID: 7
            X-CCC: US
            X-Azure-Ref-OriginShield: Ref A: 974286BFDC254CDCB50C2B73CC4B4276 Ref B: MNZ221060605025 Ref C: 2023-03-13T15:26:50Z
            X-MSEdge-Ref: Ref A: 87B54C6474A14C81B6E546C3B6B2F842 Ref B: BLUEDGE1720 Ref C: 2023-03-13T15:26:50Z
            Cache-Control: public, max-age=204313
            Date: Thu, 28 Mar 2024 22:18:54 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-03-28 22:18:54 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:23:18:45
            Start date:28/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:23:18:47
            Start date:28/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2256,i,15393059275229270124,13609790808308644620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:23:18:49
            Start date:28/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://usersync.tiqcdn.net"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly