Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://batch.cootlogix.com

Overview

General Information

Sample URL:http://batch.cootlogix.com
Analysis ID:1417318
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5628 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2028,i,16500590733582732449,9131772030437963969,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://batch.cootlogix.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://batch.cootlogix.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: batch.cootlogix.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: batch.cootlogix.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://batch.cootlogix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: batch.cootlogix.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: batch.cootlogix.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundaccess-control-allow-origin: *cache-control: max-age=0, no-cache, must-revalidate, proxy-revalidateaccess-control-allow-credentials: trueaccess-control-allow-headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, Content-Range, Cache-Controlcontent-type: application/json; charset=utf-8content-length: 43date: Thu, 28 Mar 2024 22:53:14 GMTkeep-alive: timeout=5connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not Foundaccess-control-allow-origin: *cache-control: max-age=0, no-cache, must-revalidate, proxy-revalidateaccess-control-allow-credentials: trueaccess-control-allow-headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, Content-Range, Cache-Controlcontent-type: application/json; charset=utf-8content-length: 54date: Thu, 28 Mar 2024 22:53:14 GMTkeep-alive: timeout=5connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2028,i,16500590733582732449,9131772030437963969,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://batch.cootlogix.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2028,i,16500590733582732449,9131772030437963969,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://batch.cootlogix.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://batch.cootlogix.com/favicon.ico0%Avira URL Cloudsafe
http://batch.cootlogix.com/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
istio-k8s-vidazoo-p-us-nyc1-external.vidazoo.services
178.128.132.116
truefalse
    unknown
    www.google.com
    142.251.16.104
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        hbox6nnlb.puzztake.com
        140.82.62.8
        truefalse
          unknown
          windowsupdatebg.s.llnwi.net
          69.164.0.128
          truefalse
            unknown
            batch.cootlogix.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://batch.cootlogix.com/favicon.icofalse
              • Avira URL Cloud: safe
              unknown
              https://batch.cootlogix.com/false
                unknown
                http://batch.cootlogix.com/false
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                178.128.132.116
                istio-k8s-vidazoo-p-us-nyc1-external.vidazoo.servicesNetherlands
                14061DIGITALOCEAN-ASNUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                140.82.62.8
                hbox6nnlb.puzztake.comUnited States
                20473AS-CHOOPAUSfalse
                142.251.16.104
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1417318
                Start date and time:2024-03-28 23:52:24 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 2m 56s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://batch.cootlogix.com
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@17/4@6/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.253.115.94, 142.251.16.100, 142.251.16.113, 142.251.16.101, 142.251.16.139, 142.251.16.102, 142.251.16.138, 142.251.179.84, 34.104.35.123, 20.114.59.183, 69.164.0.128, 192.229.211.108, 52.165.164.15, 20.3.187.198, 20.12.23.50, 142.251.16.94, 40.68.123.157
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: http://batch.cootlogix.com
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:JSON data
                Category:downloaded
                Size (bytes):43
                Entropy (8bit):4.268719696310996
                Encrypted:false
                SSDEEP:3:YWR4h2zd6GE/Ke8K4:YWyQK/Wp
                MD5:00BA9076E508F641510D4EE2EA53CDEF
                SHA1:45BE3EB6FEE73B32DFA9747C24C83BF613D9D6C4
                SHA-256:14DAFCBC80A313470C03A4239E13F1454BA483C4D049484C415E3E00CB5D4DFD
                SHA-512:630245CEF9837E83EF003995591F8E2C0D0D0E191D49E8EBD960D44E600C58F409AABECE7352F4496FC46BCD79A765BE877104AAB487B9517A22E6D6FFC85814
                Malicious:false
                Reputation:low
                URL:https://batch.cootlogix.com/
                Preview:{"statusCode":404,"message":"Cannot GET /"}
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:JSON data
                Category:downloaded
                Size (bytes):54
                Entropy (8bit):4.536842363074259
                Encrypted:false
                SSDEEP:3:YWR4h2zd6GE/Ke8KDETqLLMi:YWyQK/WiLMi
                MD5:F724EB23297A894BF726D26649E8E26C
                SHA1:8E22F926F08C02D69E2704923124FFF8E4B30025
                SHA-256:F639D54D7FE79AAF505BDDC5DABF737662C61D3993BF03E6D6B3B5F5453EAB69
                SHA-512:DA8FEC16AEC8321C7A0F22E7E1E97FBFBEFF88CF328EF2E8329B2B142DD3AB772A660630DE7855476E043267B6CFE2C0443DB0D3DFAF4A8A8D99689DDCACADA1
                Malicious:false
                Reputation:low
                URL:https://batch.cootlogix.com/favicon.ico
                Preview:{"statusCode":404,"message":"Cannot GET /favicon.ico"}
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Mar 28, 2024 23:53:06.310324907 CET49678443192.168.2.4104.46.162.224
                Mar 28, 2024 23:53:06.310349941 CET49675443192.168.2.4173.222.162.32
                Mar 28, 2024 23:53:13.378309965 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.378684998 CET4973680192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.478924036 CET8049735178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:13.479011059 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.479191065 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.479372978 CET8049736178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:13.479424000 CET4973680192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.580095053 CET8049735178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:13.586716890 CET8049735178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:13.639060974 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:13.687479019 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.687510967 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.687582016 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.688474894 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.688488960 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.902430058 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.902698040 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.902709007 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.903740883 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.903812885 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.904880047 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.904948950 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.905179024 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:13.905185938 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:13.949417114 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.101047039 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.101113081 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.101167917 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.101854086 CET49737443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.101867914 CET44349737140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.160144091 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.160183907 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.160269976 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.160531998 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.160543919 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.369565964 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.369853020 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.369868994 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.370224953 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.374479055 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.374545097 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.374756098 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.420234919 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.572392941 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.572454929 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:14.572504997 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.581007004 CET49740443192.168.2.4140.82.62.8
                Mar 28, 2024 23:53:14.581027985 CET44349740140.82.62.8192.168.2.4
                Mar 28, 2024 23:53:15.918555021 CET49675443192.168.2.4173.222.162.32
                Mar 28, 2024 23:53:16.133765936 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.133810997 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.133873940 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.135993958 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.136006117 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.362557888 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.363698959 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.363718033 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.364727020 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.364810944 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.370625019 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.370695114 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.418560028 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.418574095 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:16.465439081 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:16.478461981 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.478492022 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:16.478636980 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.481458902 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.481472969 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:16.830928087 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:16.830992937 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.836024046 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.836033106 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:16.836297989 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:16.887310028 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.916934967 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:16.960237026 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.165286064 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.165354013 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.165456057 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.165488005 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.165501118 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.165510893 CET49742443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.165515900 CET4434974223.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.204030037 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.204056978 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.204281092 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.204569101 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.204582930 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.556009054 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.556106091 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.559940100 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.559947014 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.560163021 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.562323093 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.604234934 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.900799990 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.900909901 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:17.900975943 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.902920008 CET49743443192.168.2.423.221.242.90
                Mar 28, 2024 23:53:17.902934074 CET4434974323.221.242.90192.168.2.4
                Mar 28, 2024 23:53:26.413832903 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:26.414016008 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:26.414128065 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:27.949573040 CET49741443192.168.2.4142.251.16.104
                Mar 28, 2024 23:53:27.949640036 CET44349741142.251.16.104192.168.2.4
                Mar 28, 2024 23:53:28.586487055 CET8049736178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:28.586601019 CET4973680192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:29.343235016 CET4973680192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:29.442970037 CET8049736178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:49.585304022 CET8049735178.128.132.116192.168.2.4
                Mar 28, 2024 23:53:49.585788965 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:49.921711922 CET4973580192.168.2.4178.128.132.116
                Mar 28, 2024 23:53:50.022087097 CET8049735178.128.132.116192.168.2.4
                Mar 28, 2024 23:54:16.092048883 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:16.092082024 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.092145920 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:16.092355967 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:16.092370987 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.299262047 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.299504995 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:16.299515963 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.299835920 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.300275087 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:16.300337076 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:16.340869904 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:25.262823105 CET4972480192.168.2.472.21.81.240
                Mar 28, 2024 23:54:25.262823105 CET4972380192.168.2.472.21.81.240
                Mar 28, 2024 23:54:25.357121944 CET804972372.21.81.240192.168.2.4
                Mar 28, 2024 23:54:25.357268095 CET4972380192.168.2.472.21.81.240
                Mar 28, 2024 23:54:25.358290911 CET804972472.21.81.240192.168.2.4
                Mar 28, 2024 23:54:25.358458042 CET4972480192.168.2.472.21.81.240
                Mar 28, 2024 23:54:26.299537897 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:26.299599886 CET44349752142.251.16.104192.168.2.4
                Mar 28, 2024 23:54:26.299777031 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:27.965838909 CET49752443192.168.2.4142.251.16.104
                Mar 28, 2024 23:54:27.965861082 CET44349752142.251.16.104192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Mar 28, 2024 23:53:11.729712963 CET53498041.1.1.1192.168.2.4
                Mar 28, 2024 23:53:11.774247885 CET53504361.1.1.1192.168.2.4
                Mar 28, 2024 23:53:12.404740095 CET53612881.1.1.1192.168.2.4
                Mar 28, 2024 23:53:13.279638052 CET6525253192.168.2.41.1.1.1
                Mar 28, 2024 23:53:13.279849052 CET5049353192.168.2.41.1.1.1
                Mar 28, 2024 23:53:13.376585007 CET53652521.1.1.1192.168.2.4
                Mar 28, 2024 23:53:13.377748013 CET53504931.1.1.1192.168.2.4
                Mar 28, 2024 23:53:13.589073896 CET5080053192.168.2.41.1.1.1
                Mar 28, 2024 23:53:13.589291096 CET5781053192.168.2.41.1.1.1
                Mar 28, 2024 23:53:13.684794903 CET53508001.1.1.1192.168.2.4
                Mar 28, 2024 23:53:13.684817076 CET53578101.1.1.1192.168.2.4
                Mar 28, 2024 23:53:16.031002045 CET6226153192.168.2.41.1.1.1
                Mar 28, 2024 23:53:16.031224966 CET5597553192.168.2.41.1.1.1
                Mar 28, 2024 23:53:16.129937887 CET53559751.1.1.1192.168.2.4
                Mar 28, 2024 23:53:16.129956961 CET53622611.1.1.1192.168.2.4
                Mar 28, 2024 23:53:29.440423965 CET53597671.1.1.1192.168.2.4
                Mar 28, 2024 23:53:36.844935894 CET138138192.168.2.4192.168.2.255
                Mar 28, 2024 23:53:48.396370888 CET53649031.1.1.1192.168.2.4
                Mar 28, 2024 23:54:10.656322956 CET53651161.1.1.1192.168.2.4
                Mar 28, 2024 23:54:11.125933886 CET53512081.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Mar 28, 2024 23:53:13.279638052 CET192.168.2.41.1.1.10x48b6Standard query (0)batch.cootlogix.comA (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:13.279849052 CET192.168.2.41.1.1.10xa4d4Standard query (0)batch.cootlogix.com65IN (0x0001)false
                Mar 28, 2024 23:53:13.589073896 CET192.168.2.41.1.1.10x877aStandard query (0)batch.cootlogix.comA (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:13.589291096 CET192.168.2.41.1.1.10x4196Standard query (0)batch.cootlogix.com65IN (0x0001)false
                Mar 28, 2024 23:53:16.031002045 CET192.168.2.41.1.1.10x3e88Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.031224966 CET192.168.2.41.1.1.10xd78dStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Mar 28, 2024 23:53:13.376585007 CET1.1.1.1192.168.2.40x48b6No error (0)batch.cootlogix.comvidazoo-p-vidazoo-openrtb-batch-tags-us-nyc1-k8s.vidazoo.servicesCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:13.376585007 CET1.1.1.1192.168.2.40x48b6No error (0)vidazoo-p-vidazoo-openrtb-batch-tags-us-nyc1-k8s.vidazoo.servicesistio-k8s-vidazoo-p-us-nyc1-external.vidazoo.servicesCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:13.376585007 CET1.1.1.1192.168.2.40x48b6No error (0)istio-k8s-vidazoo-p-us-nyc1-external.vidazoo.services178.128.132.116A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:13.377748013 CET1.1.1.1192.168.2.40xa4d4No error (0)batch.cootlogix.comhx697j1lb.puzztake.comCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:13.684794903 CET1.1.1.1192.168.2.40x877aNo error (0)batch.cootlogix.comhbox6nnlb.puzztake.comCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:13.684794903 CET1.1.1.1192.168.2.40x877aNo error (0)hbox6nnlb.puzztake.com140.82.62.8A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:13.684794903 CET1.1.1.1192.168.2.40x877aNo error (0)hbox6nnlb.puzztake.com140.82.0.94A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:13.684817076 CET1.1.1.1192.168.2.40x4196No error (0)batch.cootlogix.comhx697j1lb.puzztake.comCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:16.129937887 CET1.1.1.1192.168.2.40xd78dNo error (0)www.google.com65IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:16.129956961 CET1.1.1.1192.168.2.40x3e88No error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:29.430001974 CET1.1.1.1192.168.2.40x6152No error (0)windowsupdatebg.s.llnwi.net69.164.0.128A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:29.430001974 CET1.1.1.1192.168.2.40x6152No error (0)windowsupdatebg.s.llnwi.net69.164.0.0A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:29.737229109 CET1.1.1.1192.168.2.40xdef6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:29.737229109 CET1.1.1.1192.168.2.40xdef6No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Mar 28, 2024 23:53:42.641952991 CET1.1.1.1192.168.2.40xc21cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:53:42.641952991 CET1.1.1.1192.168.2.40xc21cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Mar 28, 2024 23:54:03.436925888 CET1.1.1.1192.168.2.40x8635No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Mar 28, 2024 23:54:03.436925888 CET1.1.1.1192.168.2.40x8635No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • batch.cootlogix.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449735178.128.132.116805628C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                Mar 28, 2024 23:53:13.479191065 CET434OUTGET / HTTP/1.1
                Host: batch.cootlogix.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Mar 28, 2024 23:53:13.586716890 CET130INHTTP/1.1 301 Moved Permanently
                location: https://batch.cootlogix.com/
                date: Thu, 28 Mar 2024 22:53:13 GMT
                content-length: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449737140.82.62.84435628C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-03-28 22:53:13 UTC662OUTGET / HTTP/1.1
                Host: batch.cootlogix.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-03-28 22:53:14 UTC438INHTTP/1.1 404 Not Found
                access-control-allow-origin: *
                cache-control: max-age=0, no-cache, must-revalidate, proxy-revalidate
                access-control-allow-credentials: true
                access-control-allow-headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, Content-Range, Cache-Control
                content-type: application/json; charset=utf-8
                content-length: 43
                date: Thu, 28 Mar 2024 22:53:14 GMT
                keep-alive: timeout=5
                connection: close
                2024-03-28 22:53:14 UTC43INData Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 22 7d
                Data Ascii: {"statusCode":404,"message":"Cannot GET /"}


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449740140.82.62.84435628C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-03-28 22:53:14 UTC594OUTGET /favicon.ico HTTP/1.1
                Host: batch.cootlogix.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://batch.cootlogix.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-03-28 22:53:14 UTC438INHTTP/1.1 404 Not Found
                access-control-allow-origin: *
                cache-control: max-age=0, no-cache, must-revalidate, proxy-revalidate
                access-control-allow-credentials: true
                access-control-allow-headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, Content-Range, Cache-Control
                content-type: application/json; charset=utf-8
                content-length: 54
                date: Thu, 28 Mar 2024 22:53:14 GMT
                keep-alive: timeout=5
                connection: close
                2024-03-28 22:53:14 UTC54INData Raw: 7b 22 73 74 61 74 75 73 43 6f 64 65 22 3a 34 30 34 2c 22 6d 65 73 73 61 67 65 22 3a 22 43 61 6e 6e 6f 74 20 47 45 54 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 7d
                Data Ascii: {"statusCode":404,"message":"Cannot GET /favicon.ico"}


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974223.221.242.90443
                TimestampBytes transferredDirectionData
                2024-03-28 22:53:16 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-03-28 22:53:17 UTC468INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus2-z1
                Cache-Control: public, max-age=202212
                Date: Thu, 28 Mar 2024 22:53:17 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974323.221.242.90443
                TimestampBytes transferredDirectionData
                2024-03-28 22:53:17 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-03-28 22:53:17 UTC774INHTTP/1.1 200 OK
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-CID: 7
                X-CCC: US
                X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
                X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
                Content-Type: application/octet-stream
                X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=202192
                Date: Thu, 28 Mar 2024 22:53:17 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-03-28 22:53:17 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:23:53:07
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:23:53:09
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2028,i,16500590733582732449,9131772030437963969,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:23:53:12
                Start date:28/03/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://batch.cootlogix.com"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly