Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg

Overview

General Information

Sample URL:http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg
Analysis ID:1417450
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4916 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2128 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,10283009642975068563,18317178896216016107,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpgHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.180.114
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg HTTP/1.1Host: siliconeer.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: siliconeer.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpgAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: siliconeer.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg HTTP/1.1Host: siliconeer.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: siliconeer.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.33.180.114:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/5@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,10283009642975068563,18317178896216016107,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,10283009642975068563,18317178896216016107,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://siliconeer.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
siliconeer.com
162.241.248.14
truefalse
    unknown
    www.google.com
    172.253.62.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpgfalse
          unknown
          https://siliconeer.com/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpgfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            162.241.248.14
            siliconeer.comUnited States
            46606UNIFIEDLAYER-AS-1USfalse
            172.253.62.105
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1417450
            Start date and time:2024-03-29 10:24:57 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 4s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@17/5@8/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.253.122.94, 142.251.167.101, 142.251.167.102, 142.251.167.138, 142.251.167.139, 142.251.167.100, 142.251.167.113, 142.251.163.84, 34.104.35.123, 20.114.59.183, 72.21.81.240, 192.229.211.108, 20.242.39.171, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
            Category:downloaded
            Size (bytes):70075
            Entropy (8bit):7.917366245670385
            Encrypted:false
            SSDEEP:1536:KQenmqrioNl5K81m8tFykTZLuX05whZPI0N9FftS9z4:xSuoN28w4ICZKX8wjXNLId4
            MD5:CA9D00D9FCD90EC59F1489F2140D6441
            SHA1:2BD6F006BDC0920686EC4102D494EB922BCBA6B9
            SHA-256:17BB1C9AABE71D47A1B25BE46F7E2565642E8B538830F6B3340BE7AB302C4F42
            SHA-512:78B38B1F722A73E9A1841F5FB28BD5F77FA406ED1693660A79031F8804A492247C061A431EAD3489FC764D5BC9521906D655C903F77A1ABC838F07236DEF667B
            Malicious:false
            Reputation:low
            URL:https://siliconeer.com/favicon.ico
            Preview:.PNG........IHDR..............x......iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about=""/>. </rdf:RDF>.</x:xmpmeta>.<?xpacket end="r"?>.J......iCCPsRGB IEC61966-2.1..(.u..KBA....(.0z@...= 4. j.dD..a..6z}.j.{...A[. j.kQ.Am..AP.A.i..M..\...3.9..f.a..X.q%.W.@"..|S........m4.Go@...9/...*3..Z...k....@U..j).ia.FJ5yW.U..B...NM.(|o......-....7..&aG...e.......D<...c...N..K...@......0....2*.0.........Y.%W.Y%...Qb.p....a....2.d......r...<P.b...P....a|..F....p.,.......u..-...i.=...'5...U......4.A.-..zV.......U7...=r...}yg.Yb.6....pHYs............... .IDATx..wx.....KB(.=.&..*.... ..H..z.M..^E..A..(. bA...".4!.RC }...^.....7..Qr;.3....wgg..... ..i=.. ..u..?....,."!..A(..\..%._\.........L_./..<...@ ..b[.k..9....).........!.j.5#..d.......#..Q.x.p.@.u........s...@@:.Hd.(3..B.X....P.....}....x
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1080, components 3
            Category:downloaded
            Size (bytes):58819
            Entropy (8bit):7.942409681103454
            Encrypted:false
            SSDEEP:1536:mhaLoz+vqpt+0yQ8rsmaES25p1pqgyFruS:mgLoz+vNQsN3qJuS
            MD5:4AE075B7907D4CF76A82EB3227F0B706
            SHA1:8A17D26DEDFA731647607F7E46E04B3F30509EA2
            SHA-256:FAD4F0CE601E4134978D58A68901122D0324249DB645141D5539CC317BB210A4
            SHA-512:B4082EB102BC9757285F87322CDCBF9F915738D0C1688E72B980A45887D22CA31CED2F639DA7B27196FA628B90A4EE6A35132A445D6B581C81B2351F49919A9F
            Malicious:false
            Reputation:low
            URL:https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg
            Preview:......JFIF.............C.....................................%...#... , #&')*)..-0-(0%()(...C...........(...((((((((((((((((((((((((((((((((((((((((((((((((((......8.8.."...............................................................................9Vi ...l...lm...VXm...D...-.....m..VJ2....f.0.Kt.+h.+Y.j#...J.&.7.r..)A..z<=.A)wi.unA_..3z....GKH3p...:%..-....:eL.A.......b..........`.%F..@1...l`B2..mf.F...X.m.{...*... ....lm....l... ...d..ei.....D..:!........BV.V...1..&.K...$.hx{.S.~.....:V..O?W);.CK..o.......Lr.w.hb....gd..+f"H..a....).c.@6.<Ti)Q...................um.{...:*... ....lm....l... .D...e$.,..:Q...4.E.GO?J_...kF.J#......3........)....,..(U.k..E.-w-.4...$Vi..:.4.R]...."..!R&8..R...Ul...6|K?A4...Frer. ..gT\.F!.`..A.M.M...6.=..VM..A....m..6.].6.q..A..I.h..E..4.Q.f...L:...V.R.q..VA8.<.g...5uQy.-.3...r.C..'..'?b.=&..H.#.t.).F.....g......|]vr.TZ......f..M:dy.......e..f..2...E.(...dm.m..6..eI.4tU...@.].6..aYZ6.q..A.;l. ......j%..+3n.....K.7J.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):70075
            Entropy (8bit):7.917366245670385
            Encrypted:false
            SSDEEP:1536:KQenmqrioNl5K81m8tFykTZLuX05whZPI0N9FftS9z4:xSuoN28w4ICZKX8wjXNLId4
            MD5:CA9D00D9FCD90EC59F1489F2140D6441
            SHA1:2BD6F006BDC0920686EC4102D494EB922BCBA6B9
            SHA-256:17BB1C9AABE71D47A1B25BE46F7E2565642E8B538830F6B3340BE7AB302C4F42
            SHA-512:78B38B1F722A73E9A1841F5FB28BD5F77FA406ED1693660A79031F8804A492247C061A431EAD3489FC764D5BC9521906D655C903F77A1ABC838F07236DEF667B
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............x......iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about=""/>. </rdf:RDF>.</x:xmpmeta>.<?xpacket end="r"?>.J......iCCPsRGB IEC61966-2.1..(.u..KBA....(.0z@...= 4. j.dD..a..6z}.j.{...A[. j.kQ.Am..AP.A.i..M..\...3.9..f.a..X.q%.W.@"..|S........m4.Go@...9/...*3..Z...k....@U..j).ia.FJ5yW.U..B...NM.(|o......-....7..&aG...e.......D<...c...N..K...@......0....2*.0.........Y.%W.Y%...Qb.p....a....2.d......r...<P.b...P....a|..F....p.,.......u..-...i.=...'5...U......4.A.-..zV.......U7...=r...}yg.Yb.6....pHYs............... .IDATx..wx.....KB(.=.&..*.... ..H..z.M..^E..A..(. bA...".4!.RC }...^.....7..Qr;.3....wgg..... ..i=.. ..u..?....,."!..A(..\..%._\.........L_./..<...@ ..b[.k..9....).........!.j.5#..d.......#..Q.x.p.@.u........s...@@:.Hd.(3..B.X....P.....}....x
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 29, 2024 10:25:39.867413044 CET49675443192.168.2.4173.222.162.32
            Mar 29, 2024 10:25:40.226790905 CET49678443192.168.2.4104.46.162.224
            Mar 29, 2024 10:25:47.171159029 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.171624899 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.276412964 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.350564957 CET8049735162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.350802898 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.351012945 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.351881981 CET8049736162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.351946115 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.457201958 CET8049737162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.457432985 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.530145884 CET8049735162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.535043001 CET8049735162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.577341080 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.739294052 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.739331961 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:47.739417076 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.739629030 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:47.739638090 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.110450983 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.110738993 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.110758066 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.111623049 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.111696005 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.112670898 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.112724066 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.112909079 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.112914085 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.167916059 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.474047899 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.474069118 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.474076986 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.474111080 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.474118948 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.474128962 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.474163055 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.523128986 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654072046 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654082060 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654113054 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654171944 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654186010 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654194117 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654212952 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654218912 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654230118 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654256105 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654405117 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654431105 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.654450893 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.654478073 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.745781898 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.745793104 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.745872021 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.834517956 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.834599018 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.834656954 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.834698915 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.834718943 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.834723949 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:48.834736109 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:48.875813007 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.287267923 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.328233957 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.474503040 CET49675443192.168.2.4173.222.162.32
            Mar 29, 2024 10:25:49.498445988 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.498495102 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.498522997 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.498560905 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.499047041 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499053955 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499098063 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.499108076 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499537945 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499603033 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.499607086 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499792099 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.499856949 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.499861002 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500109911 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500163078 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.500168085 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500325918 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500390053 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.500395060 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500587940 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500642061 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.500646114 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500855923 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.500911951 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.500916004 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.553762913 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.679363966 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.679398060 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:49.679450035 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:49.679478884 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.026942968 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.026978970 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.027034998 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.027668953 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.027687073 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.138520956 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.138564110 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.138641119 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.139830112 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.139836073 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.239315987 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.289515018 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.309791088 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.309799910 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.310734987 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.310794115 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.318856001 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.318916082 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.366297007 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.366312027 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:25:50.413170099 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:25:50.508842945 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.522542000 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.522567987 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.523478031 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.523545027 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.527023077 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.527077913 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.529519081 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.529529095 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.569416046 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.899321079 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.899348974 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.899355888 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.899418116 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:50.899435043 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:50.944417953 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.063847065 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.063873053 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.063951969 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.067051888 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.067063093 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.079263926 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079272032 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079302073 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079324007 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.079354048 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.079365969 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079375982 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079425097 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.079433918 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079608917 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079641104 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079658031 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.079663992 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.079674959 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.137002945 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.144670010 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.144679070 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.144705057 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.144751072 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.144790888 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.261588097 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.261596918 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.261667967 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.261679888 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.261919022 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.261926889 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.261969090 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.261976957 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.262309074 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.262346029 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.262367010 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.262373924 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.262399912 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.262486935 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.262536049 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.262542009 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:51.268369913 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.268435955 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.271207094 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.271212101 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.271496058 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.303798914 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:51.311029911 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.356246948 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.455460072 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.455611944 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.455661058 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.455738068 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.455753088 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.455764055 CET49743443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.455768108 CET4434974323.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.511360884 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.511398077 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.511543036 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.511850119 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.511862040 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.706536055 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.706584930 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.744328022 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.744338989 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.744600058 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.750070095 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.792241096 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.897145987 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.897222042 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.897464991 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.900038958 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.900053978 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:51.900063038 CET49744443192.168.2.423.33.180.114
            Mar 29, 2024 10:25:51.900067091 CET4434974423.33.180.114192.168.2.4
            Mar 29, 2024 10:25:52.535872936 CET8049735162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:52.535933018 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:53.898169994 CET4973580192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:54.078258991 CET8049735162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:54.680058002 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:54.680135965 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:54.680186033 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:55.883497000 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:55.883517027 CET44349738162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:55.883549929 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:55.883589029 CET49738443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:56.098493099 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:56.098561049 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:56.098613024 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:58.805921078 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:58.805921078 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:25:58.805958986 CET44349742162.241.248.14192.168.2.4
            Mar 29, 2024 10:25:58.806005001 CET49742443192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:00.262904882 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:00.262974977 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:00.263065100 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:01.890187979 CET49741443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:01.890218973 CET44349741172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:19.171631098 CET8049737162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:19.171652079 CET8049736162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:19.171694040 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:19.171727896 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:32.366353035 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:32.460172892 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:32.546756983 CET8049736162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:32.647322893 CET8049737162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:47.907063007 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:47.907150030 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:48.086977005 CET8049737162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:48.087033987 CET4973780192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:48.087506056 CET8049736162.241.248.14192.168.2.4
            Mar 29, 2024 10:26:48.087559938 CET4973680192.168.2.4162.241.248.14
            Mar 29, 2024 10:26:49.978214979 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:49.978246927 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:49.978317022 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:49.979023933 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:49.979034901 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:50.186177015 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:50.186497927 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:50.186510086 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:50.186799049 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:50.187210083 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:26:50.187263012 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:26:50.241985083 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:27:00.195698977 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:27:00.195765018 CET44349753172.253.62.105192.168.2.4
            Mar 29, 2024 10:27:00.195907116 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:27:01.883804083 CET49753443192.168.2.4172.253.62.105
            Mar 29, 2024 10:27:01.883829117 CET44349753172.253.62.105192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Mar 29, 2024 10:25:45.809784889 CET53514671.1.1.1192.168.2.4
            Mar 29, 2024 10:25:45.813394070 CET53520101.1.1.1192.168.2.4
            Mar 29, 2024 10:25:46.537940979 CET53521071.1.1.1192.168.2.4
            Mar 29, 2024 10:25:47.000965118 CET5447153192.168.2.41.1.1.1
            Mar 29, 2024 10:25:47.001102924 CET6163753192.168.2.41.1.1.1
            Mar 29, 2024 10:25:47.158540010 CET53544711.1.1.1192.168.2.4
            Mar 29, 2024 10:25:47.170387983 CET53616371.1.1.1192.168.2.4
            Mar 29, 2024 10:25:47.538862944 CET6144253192.168.2.41.1.1.1
            Mar 29, 2024 10:25:47.539278030 CET6114553192.168.2.41.1.1.1
            Mar 29, 2024 10:25:47.691262007 CET53611451.1.1.1192.168.2.4
            Mar 29, 2024 10:25:47.738606930 CET53614421.1.1.1192.168.2.4
            Mar 29, 2024 10:25:49.922795057 CET5415253192.168.2.41.1.1.1
            Mar 29, 2024 10:25:49.928520918 CET5819653192.168.2.41.1.1.1
            Mar 29, 2024 10:25:49.992733955 CET6458253192.168.2.41.1.1.1
            Mar 29, 2024 10:25:49.993011951 CET6350053192.168.2.41.1.1.1
            Mar 29, 2024 10:25:50.018346071 CET53541521.1.1.1192.168.2.4
            Mar 29, 2024 10:25:50.023310900 CET53581961.1.1.1192.168.2.4
            Mar 29, 2024 10:25:50.089766026 CET53645821.1.1.1192.168.2.4
            Mar 29, 2024 10:25:50.090073109 CET53635001.1.1.1192.168.2.4
            Mar 29, 2024 10:26:04.791656017 CET53539711.1.1.1192.168.2.4
            Mar 29, 2024 10:26:10.765511036 CET138138192.168.2.4192.168.2.255
            Mar 29, 2024 10:26:23.666378021 CET53545581.1.1.1192.168.2.4
            Mar 29, 2024 10:26:45.212831020 CET53629881.1.1.1192.168.2.4
            Mar 29, 2024 10:26:46.569067001 CET53570621.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 29, 2024 10:25:47.000965118 CET192.168.2.41.1.1.10x69beStandard query (0)siliconeer.comA (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:47.001102924 CET192.168.2.41.1.1.10xe285Standard query (0)siliconeer.com65IN (0x0001)false
            Mar 29, 2024 10:25:47.538862944 CET192.168.2.41.1.1.10xbd4dStandard query (0)siliconeer.comA (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:47.539278030 CET192.168.2.41.1.1.10x34d1Standard query (0)siliconeer.com65IN (0x0001)false
            Mar 29, 2024 10:25:49.922795057 CET192.168.2.41.1.1.10xd3a3Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:49.928520918 CET192.168.2.41.1.1.10x6ea6Standard query (0)www.google.com65IN (0x0001)false
            Mar 29, 2024 10:25:49.992733955 CET192.168.2.41.1.1.10xe971Standard query (0)siliconeer.comA (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:49.993011951 CET192.168.2.41.1.1.10xde59Standard query (0)siliconeer.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 29, 2024 10:25:47.158540010 CET1.1.1.1192.168.2.40x69beNo error (0)siliconeer.com162.241.248.14A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:47.738606930 CET1.1.1.1192.168.2.40xbd4dNo error (0)siliconeer.com162.241.248.14A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.105A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.147A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.104A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.99A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.103A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.018346071 CET1.1.1.1192.168.2.40xd3a3No error (0)www.google.com172.253.62.106A (IP address)IN (0x0001)false
            Mar 29, 2024 10:25:50.023310900 CET1.1.1.1192.168.2.40x6ea6No error (0)www.google.com65IN (0x0001)false
            Mar 29, 2024 10:25:50.089766026 CET1.1.1.1192.168.2.40xe971No error (0)siliconeer.com162.241.248.14A (IP address)IN (0x0001)false
            Mar 29, 2024 10:26:03.576436043 CET1.1.1.1192.168.2.40x4347No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 10:26:03.576436043 CET1.1.1.1192.168.2.40x4347No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 29, 2024 10:26:16.666083097 CET1.1.1.1192.168.2.40xffd7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 10:26:16.666083097 CET1.1.1.1192.168.2.40xffd7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 29, 2024 10:26:38.747472048 CET1.1.1.1192.168.2.40xe43dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 10:26:38.747472048 CET1.1.1.1192.168.2.40xe43dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Mar 29, 2024 10:26:57.946441889 CET1.1.1.1192.168.2.40x702fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Mar 29, 2024 10:26:57.946441889 CET1.1.1.1192.168.2.40x702fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • siliconeer.com
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735162.241.248.14802128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 29, 2024 10:25:47.351012945 CET524OUTGET /current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg HTTP/1.1
            Host: siliconeer.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9
            Mar 29, 2024 10:25:47.535043001 CET664INHTTP/1.1 301 Moved Permanently
            Date: Fri, 29 Mar 2024 09:25:47 GMT
            Server: Apache
            Location: https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg
            Content-Length: 326
            Keep-Alive: timeout=5, max=75
            Connection: Keep-Alive
            Content-Type: text/html; charset=iso-8859-1
            Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 73 69 6c 69 63 6f 6e 65 65 72 2e 63 6f 6d 2f 63 75 72 72 65 6e 74 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 75 70 6c 6f 61 64 73 2f 32 30 32 30 2f 30 37 2f 68 61 72 73 68 2d 63 68 68 61 79 61 2d 69 2d 68 61 76 65 2d 6e 6f 74 68 69 6e 67 2d 61 67 61 69 6e 73 74 2d 77 6f 72 6b 69 6e 67 2d 69 6e 2d 61 2d 74 76 2d 73 68 6f 77 2e 6a 70 67 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg">here</a>.</p></body></html>


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449736162.241.248.14802128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 29, 2024 10:26:32.366353035 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.449737162.241.248.14802128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 29, 2024 10:26:32.460172892 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449738162.241.248.144432128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-29 09:25:48 UTC752OUTGET /current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg HTTP/1.1
            Host: siliconeer.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-29 09:25:48 UTC420INHTTP/1.1 200 OK
            Date: Fri, 29 Mar 2024 09:25:48 GMT
            Server: Apache
            Upgrade: h2,h2c
            Connection: Upgrade
            Last-Modified: Fri, 10 Jul 2020 12:04:10 GMT
            Accept-Ranges: bytes
            Content-Length: 58819
            Cache-Control: max-age=10368000, public
            Expires: Sat, 27 Jul 2024 09:25:48 GMT
            host-header: d3AuYmx1ZWhvc3QuY29t
            Vary: Accept-Encoding
            X-Endurance-Cache-Level: 0
            X-nginx-cache: WordPress
            Content-Type: image/jpeg
            2024-03-29 09:25:48 UTC7772INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 06 04 05 06 05 04 06 06 05 06 07 07 06 08 0a 10 0a 0a 09 09 0a 14 0e 0f 0c 10 17 14 18 18 17 14 16 16 1a 1d 25 1f 1a 1b 23 1c 16 16 20 2c 20 23 26 27 29 2a 29 19 1f 2d 30 2d 28 30 25 28 29 28 ff db 00 43 01 07 07 07 0a 08 0a 13 0a 0a 13 28 1a 16 1a 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 ff c2 00 11 08 04 38 04 38 03 01 22 00 02 11 01 03 11 01 ff c4 00 1b 00 00 03 01 01 01 01 01 00 00 00 00 00 00 00 00 00 01 02 03 00 04 05 06 07 ff c4 00 1a 01 01 01 01 01 01 01 01 00 00 00 00 00 00 00 00 00 00 01 02 03 04 05 06 ff da 00 0c 03 01 00 02 10 03 10 00 00 01 f8 39 56 69 20 c8 aa
            Data Ascii: JFIFC%# , #&')*)-0-(0%()(C(((((((((((((((((((((((((((((((((((((((((((((((((((88"9Vi
            2024-03-29 09:25:48 UTC8000INData Raw: d1 9d 1f 3a 62 1a 69 99 5b 3b 7b c2 d3 4c 30 55 38 43 ab a5 04 60 bc 7c bd fc 18 eb e6 f1 7a 1e 7e 7a 41 83 55 7d 1f 9d e0 d7 3f b9 6f 8b f6 ee 3d 6e 6e c8 e3 af 99 cd df c7 3a 70 52 4d ac fd 17 a5 e6 7a 7a e5 46 5d 32 f8 22 d0 29 4d 88 50 08 20 b7 96 74 b0 ba 33 2e 5b cc 9c fa 12 ea 13 b7 28 ea 66 2c ac 00 19 44 97 47 2a 4f 19 5c 84 72 0c f8 4c c8 1c 08 d0 a2 54 75 27 ac 46 75 9a 47 9b a7 97 78 5d b6 b1 ef 4a d1 eb c2 49 49 88 ac a0 57 51 55 80 01 c0 04 4b b6 c0 db 29 db 07 6d 34 59 59 a7 a4 eb 9b 5b 47 a1 7a 3a f9 7b 13 ab b3 97 a9 3a ba 79 ba 92 fd 10 be a5 6b 3a 33 46 0c 6c 70 a0 81 55 90 54 65 cd 98 2a 00 42 8d b4 16 56 ce 99 91 f3 b6 65 6c e9 de 6d 35 65 2a a1 4a ca e2 6a a5 27 9a 3c b4 e7 ce f8 38 7d 0e 1c f5 97 98 3c 1e de 7d bb fa f7 cf c1 de f7
            Data Ascii: :bi[;{L0U8C`|z~zAU}?o=nn:pRMzzF]2")MP t3.[(f,DG*O\rLTu'FuGx]JIIWQUK)m4YY[Gz:{:yk:3FlpUTe*BVelm5e*Jj'<8}<}
            2024-03-29 09:25:48 UTC8000INData Raw: 52 1e 85 28 4e 68 8e ac 48 a8 c8 da 8f b7 4f f2 35 34 1a 2a 8d 16 a6 b6 b2 5a 4f 76 94 76 91 87 75 66 ca 2b dc 7c df 19 0f 8d 0c 65 b2 d9 63 63 1a c5 61 fb 8c 7f c0 42 22 44 89 12 22 10 b8 cf c6 ba 48 d5 8f dc 8e dd a2 fb b5 f7 66 4f b6 a7 d6 dd d0 52 f4 c7 55 a8 fd 3c d2 36 a6 e1 1a 70 9c 19 28 c1 0f 4d 5c b6 b3 ed 51 bf b7 b6 b6 4e e2 a4 6d 99 b6 ca 67 da dc 47 4b 6b a3 f5 15 d4 3c 55 15 ee be 6f 0f 2c 92 18 b2 d1 37 47 93 c6 36 09 45 0e 5a 67 91 f7 8b 2b 95 f2 63 f9 e8 42 11 12 24 44 21 73 9c 6c 8c 5c 47 a0 e4 bc 0e 72 6e 6c 64 67 b2 4f b1 5b 20 9a 12 dc a2 a2 d7 da 22 8a 44 a2 54 91 b7 71 f6 cf b6 6d a2 2c ab 14 4d a5 1b 0d a6 de 55 cd f0 7e e4 89 62 38 64 89 14 7a d9 b4 65 96 77 89 46 b8 3f 65 ff 00 01 08 89 12 22 22 21 0b 9c 95 aa ef 57 74 5d e9 ca
            Data Ascii: R(NhHO54*ZOvvuf+|eccaB"D"HfORU<6p(M\QNmgGKk<Uo,7G6EZg+cB$D!sl\GrnldgO[ "DTqm,MU~b8dzewF?e""!Wt]
            2024-03-29 09:25:48 UTC8000INData Raw: a7 02 b6 92 f0 31 89 11 89 49 12 3f 6d d9 e4 63 1f c2 42 22 44 89 12 24 48 88 88 bf a2 85 ec c8 91 15 d1 2e df 96 c4 cf 31 fa b8 fa 3f 7f 4e 2e a1 31 79 dc 5e 59 59 6c 62 ec d5 95 47 43 4f 73 5d 0e 64 e5 6f 4a 22 8d 12 78 6c f2 24 24 42 24 91 26 48 6c bb 18 c7 f0 d1 12 24 08 91 22 22 22 17 f2 df 38 fb 32 74 bc c9 74 ec 96 17 78 7e 35 d7 4f f2 fa 51 bf 44 ea a2 5f 6f cc 46 b3 63 75 c2 b7 ce 09 45 74 4b b2 31 ee 11 a2 cb 1f 58 ad a2 ec 48 fc 49 3a 1b ca 3f ff c4 00 28 11 00 02 02 00 05 04 02 03 01 01 01 00 00 00 00 00 00 01 02 11 10 12 20 40 50 03 21 30 31 32 41 04 13 60 22 51 80 ff da 00 08 01 03 01 01 3f 01 ff 00 d0 f5 ce d1 46 52 8a 28 ae 6b 29 94 ca 24 51 94 a2 bc 2d 71 b5 85 63 45 6a 5a de 87 c4 ae e5 14 51 58 d6 d1 f1 31 45 6e 9e e1 6c 22 85 db 76 f8
            Data Ascii: 1I?mcB"D$H.1?N.1y^YYlbGCOs]doJ"xl$$B$&Hl$"""82ttx~5OQD_oFcuEtK1XHI:?( @P!012A`"Q?FR(k)$Q-qcEjZQX1Enl"v
            2024-03-29 09:25:48 UTC8000INData Raw: e6 87 f5 02 76 61 7e c7 60 4c c5 9c f3 b8 ef b7 5e 09 20 7d 71 33 38 65 96 b6 cf 8e 49 b3 13 20 78 4b ce 1e f8 65 c8 76 6c 96 7a 27 bb 26 1e 13 8b ec 3f 02 0d bf ae 26 33 bb 5b d1 0f b4 b9 f7 69 fb 61 7a 76 8c f0 e4 a7 a1 7f 8c fe 84 bf 1f f8 90 f4 9f d5 97 3d 94 99 27 f0 19 9e 5f 8b f9 ce 4e 07 e3 5a 08 e5 99 f1 97 48 74 f6 03 77 f4 46 49 b7 b7 63 6d fd 13 0b 49 22 73 f8 f5 0b 6e 17 e8 24 05 bf 48 43 00 2c ce 08 78 26 59 96 43 bb 3e 59 f2 c9 07 e0 36 cb 62 61 d4 4c af c1 b9 7b cb 0b d5 f7 c9 f8 36 b6 5e a4 c9 da b3 b7 49 06 74 09 7e 66 58 7a b3 07 c9 32 d9 3f b9 53 ee 56 3f 71 91 18 7e 0b 33 ff 00 21 c9 c1 11 1c a2 1f 14 23 81 13 33 3e 36 dc ed dd cf bc e0 51 8a 1d 74 07 dd a6 e9 26 a4 2f ff 00 92 60 d1 7d b3 35 ef ad 93 c8 fc 1b ea 4b 2c fc 7d db 93 ab
            Data Ascii: va~`L^ }q38eI xKevlz'&?&3[iazv='_NZHtwFIcmI"sn$HC,x&YC>Y6baL{6^It~fXz2?SV?q~3!#3>6Qt&/`}5K,}
            2024-03-29 09:25:48 UTC8000INData Raw: de ef 06 3e c8 6f 6a c1 e6 ed ce cc fd 4e 9e dd f7 0c b6 3d 76 de 64 c2 67 77 d8 dd 07 72 3b 1e 10 e9 44 43 37 ab b6 51 85 bc c1 b3 bd 52 f5 99 24 da 99 7f fa ba 43 2d 99 37 3a 97 5d c6 99 f5 d4 15 dc 2c b7 38 c4 64 d9 76 86 4c ac e0 c0 98 c7 de 15 87 75 bd 60 da 30 fa 97 37 24 57 47 2e cc 9e cc 85 d9 96 fa ce 6e bb 2c ef e9 b1 b3 33 ac bc b3 6d 5e 66 67 97 86 67 f0 9c 11 f9 cf f0 7c 59 99 99 fc 04 70 7c 93 8b db 65 35 12 e8 77 62 f6 ec ed 0f 90 33 23 36 ae ce 5d db 03 1c ee 07 6c 0f 76 5f bb 1f 20 91 e9 64 5d 24 c2 64 61 7e f7 49 4e 84 b3 45 a1 d2 d3 ba 5d 62 de 35 82 f1 5c bb 4a 70 98 59 12 32 cc ba b4 e8 85 55 a0 4c af 90 1f 01 1e 30 2f bc 6e 78 12 77 b9 92 2c 87 b7 47 a6 5b db 0d ec 98 c4 de ce 0d 09 65 83 78 d0 96 79 19 f9 3c 3f 84 e0 8f ce e9 83 e2
            Data Ascii: >ojN=vdgwr;DC7QR$C-7:],8dvLu`07$WG.n,3m^fgg|Yp|e5wb3#6]lv_ d]$da~INE]b5\JpY2UL0/nxw,G[exy<?
            2024-03-29 09:25:48 UTC8000INData Raw: 00 fd 4e aa 8f 57 f5 10 bc 7e 4c eb ac 9b 57 b0 72 fe d3 d2 02 45 6c e7 d3 ef 10 1e 73 a8 3a ef 0f ef be fe de 7c f2 2e b7 df d1 7f 2f f5 7f 03 de 9e 7b ef fd 5e b7 fd f7 81 fd 30 01 79 30 f9 87 56 4f 3b 97 38 a5 93 8c 19 e6 be 3f 20 04 30 a8 3a eb 5f ef be ff 00 f2 7c 21 e1 8b ff 00 d5 7d bf d5 7b 53 fa d6 5b ef ff 00 fa b7 a6 1f c8 89 1a 30 0e e9 a5 ef 14 f4 4a cb fa d5 dc 11 e3 27 5f 0b 80 04 3e b8 3a eb 5f ef be ff 00 fa 20 f2 af ef 8d 16 75 ff 00 d5 6b 63 db 9e 5f ef fd 5a be af cb 2a 08 c0 d5 cf ab b6 cc 4d b4 60 bb aa b6 6d e1 8b 4a 0f 87 b2 45 01 a8 3a eb 5f ef be fd 7a 41 c5 70 f7 1c 9a 55 5f d5 7b 23 fb ba 5b ff 00 fa 58 3a fa 5b 23 37 dd 7b 8c 6b d6 64 2a 66 f5 70 5d fe 1e ba eb 3b 9e cf cc 49 32 a8 35 eb 5f ef be a8 7f 55 16 b7 49 76 9a 55 5d
            Data Ascii: NW~LWrEls:|./{^0y0VO;8? 0:_|!}{S[0J'_>:_ ukc_Z*M`mJE:_zApU_{#[X:[#7{kd*fp];I25_UIvU]
            2024-03-29 09:25:48 UTC3047INData Raw: 04 09 20 00 44 2c 16 81 8a 1a 10 47 03 30 3e c4 e1 41 48 06 d7 00 14 09 a2 34 10 04 70 0c 20 00 8c 31 48 02 6a 54 40 f1 70 00 15 80 00 00 8e 22 25 44 23 8a 00 01 4a 55 44 82 98 00 06 05 8f 80 08 81 0a 84 12 e0 51 cd b1 52 00 02 10 50 10 c8 50 16 31 0a 00 8b 11 a8 03 23 16 8a c3 98 80 9c 43 f7 5a 0d 84 a0 3d 18 e4 00 31 28 20 3b f0 01 90 50 20 20 08 20 48 02 00 04 04 10 0d e0 10 00 10 04 08 20 90 13 08 04 19 00 42 c8 60 c1 fc 92 17 d8 5d 0b 44 fd 03 08 f4 91 c0 f4 03 83 a0 9e 70 02 01 09 b0 58 09 82 10 09 10 60 35 00 62 0d 80 10 aa 13 48 43 3a 80 46 05 40 00 80 23 12 48 9b c8 82 35 04 00 53 d0 a0 e0 50 08 0c 06 f6 00 0c dc 1c 90 db a0 92 00 82 50 04 90 40 00 0c e0 00 3c de 02 01 51 b0 09 24 58 40 41 00 5a 22 4e 10 70 09 b8 86 86 01 e0 41 7c 00 12 00 10 9d
            Data Ascii: D,G0>AH4p 1HjT@p"%D#JUDQRPP1#CZ=1( ;P H B`]DpX`5bHC:F@#H5SPP@<Q$X@AZ"NpA|
            2024-03-29 09:25:49 UTC679OUTGET /favicon.ico HTTP/1.1
            Host: siliconeer.com
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-29 09:25:49 UTC8192INHTTP/1.1 200 OK
            Date: Fri, 29 Mar 2024 09:25:49 GMT
            Server: nginx/1.21.6
            Content-Type: image/x-icon
            Content-Length: 70075
            Last-Modified: Sun, 25 Apr 2021 23:32:15 GMT
            Cache-Control: max-age=604800
            Expires: Sat, 30 Mar 2024 23:48:41 GMT
            host-header: d3AuYmx1ZWhvc3QuY29t
            X-Server-Cache: true
            X-Proxy-Cache: HIT
            Accept-Ranges: bytes
            PNG
            IHDRxiTXtXML:com.adobe.xmp<?xpacket begin="" id="W5M0MpCehiHzreSzNTczkc9d"?>
            <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">
            <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
            <rdf:Description rdf:about=""/>
            </rdf:RDF>
            </x:xmpmeta>
            <?xpacket end="r"?>JiCCPsRGB IEC61966-2.1(uKBA(0z@= 4 jdDa6z}j{A[ jkQAmAPAiM\39faXq%W@"|Sm4Go@9/*3Zk@Uj)iaFJ5yWUBNM.(|o-7&aGeD<cN.K@02*0.
            Y%WY%Qbpa2dr<PbPa|Fp,u-.i='5U4.A-zVU7=r}ygYb6pHYs IDATxwxKB(=&*
            HzM^EA( bA"4!RC }^7Qr;3wgg i= u?,"!A(\%_\L_/<@ b[k9)!j5#d#Qxp@us@@:Hd(3BXP}x@36s#%1Mx@}`^Q\)@ -BDlF*8nQ%C !!2'"H7gRA{nN-P#j
            2!k+A{nvWPjPS$9k4!/@ C`n`@"@ S7Rt4!@g?7;hH
            @}#jC@ #jJ>P2VdP@6@ 0@h`dBqW9vd&Qcah_<(Q*|~@\Y,)JzNhoYm@ &B>&~PP=8}#[Wk;}0j'ZW}PgkC@ '&Sxrm@ BbSyf`m@ b@(A1rFJo(
            rg5!@e`#O/y51,a@ B^G|BA8z~%%9*<x xg
            OFE3yOhoyM#@E(F@5O@I^Cx/nzP|('g!Fj2nGx1X
            @MoHl)s(k@a|m@`P@F("LJgIzAHPI0un:Pe9t811`l2r6Pb9ao7"/#I$#H
            KZ6 +\,zYFJI^bd$*<O8mnz9)PP?O~7!|/Fbn S
            5_t!&2]cc@`!>g$nT%|"@1_#{mk>}.al*Bb3kI;1hcu'L(8QeK!g4?;zQS7>v`cA
            zgY/L@I;ow\=).O^s"R@ p!^g5UsmJ
            7j:;I(p@>ul7rib1EfXqA"<uXj~k $<rl?6BDxGf:j0wrO@bf={.._8z`Z/l;{muu^c;r45?)phc6--k_aNNr>zEp%F8zE {kmd/Y9(\|~}QUW-qOma@qr4T>zC4~p??jm"@7g9<(.X!?a&&<,ew/7B<}K[D;xO(VynaDN70OsL_UtS40 [m?noV((bcu.N}2UcfFw91tcZWb_x,nsct%f:Ill{4D>V"eDAG<S@P(?y.XePSJO@gziB))O=0jX!*eJ
            B}`51%)rs|mKlCAc{^='D@y2p'~a8WnPT"-yrXNA@VZ`'<o\51S)<l.vE@yvA=s97"m<g._Y`t,v=~
            Me]m'M(5=S6VzKlxv@~JMU !n%'_n"@eS[t}@"!>4-y_2s~d-a~_0Y}s;p3M8&!vZ|,`Z@Pjv2a Lu?5`*fQ>BA@>Q8Gy"@q6" ;hrBA)J6vORMn#tNWol!K*;`^R"Tt>w$U}'@OzNul[ W&!bF~_Z^tTU'Rax@0BJwYsGE|"hzn(5Q@^Scsu 7(@2/^L:pC:6@.6y["! u>x^Zg<R!.##%t\CNanZ.j u;^w0'@2B\PWOn1lMNgl[)3l7U;xV'qK#p'Oy@oP0V~=73-y
            OFkanv*seF^PZ@`!.kCx_N'=)r96Z(|m:)8,g\@<!cO9.f`Q}/]0~{<Bpz\@<eE4f%2^Xq3QSxxTV~0y's69RBf=Ph!sxOdn*S7et@$BGF?&!>hm4FB'@uv@`!/"+q- _rTWpuqIP pBa"@inl8F1#'<'@JlhJh-$ pp";F6"O\dTZ |rJD+E>$R#S1C<'@8kl*Te1&N:~0rl"pm'&>&<LA>D<%+ pFgMLv
            zBaqh1mg9
            ZGwPx\/84+fBlu0~S1Kv7
            o:1w<Pg@
            d:?D\xX?n"v^xx3wtP*=.um!@ZZpj)cW?MK'3F Q:T-L"ysNlf?$tP@<8(!goY)yfpC*rKT;!~rc<J>R Q9L
            1j,RKn,8p3O4l3'W|D(TyLq ";B
            {4sxWSSN3+#{([1_'PcN3oj#5[ya$j#olY3\BxnFqM< `:\S+'mb(r5k7-+P,P<R0y;Wj)1is|[FD@!=8<s#?V/+"SJ=@A;1x
            @sY)Ncjn@v#E&rxlu]A@m-hh !r8D*1:c@TU_;ehbOJy7jI:"c:WW->hsM~I'rk3(0^={e6c/{\^=
            M~cNkP#zgCG5[i@_1Am8r H"Eow&sgl4uL`.goj0m9~uTJ|!)@4ux:yys7DnB3>Hl/;v~ox?@_uBn}N
            `m>prPO%g+jlY-J{W=QS`=LrCp<{Cie'rmQ"@{J?OH4^/Bbr#Bn}#dv#c@+r.]_4"I"&EF>)ClI( 561vNb.I<*8(%1O
            F(;m09@G6$X}&`lJ2gW0RiG`I]7UGfyz~j&_hD3M;f%PUZ<u(#?1bO#wq;EopD8z=5[a\A#@)HD?h@8 I]H:<XQ+Je$"=V?q"$sD^'*3>OgvhLmsEbE?romV7rf8leG_W.M6*x')!]oygMdH2,@u*^ukl' G)@^6' @':Kk~YicL0#D'bZg'\x)#!"<.~0}K(*9p3cDvw~oyBreUSVw,21O-`?1o)&<wqV!Nwhe;l>}!86x9cf6ZBW
            9]2W$0=iZeSQ`&,_+nf+!x=z\YW,w
            `-o8\)?SO)DPzj&i?-buqwMvO%/}{S#Cu@&xZev/N~y:gH
            {k!kXuM'Qk" Bv' nAO/~XY.?dyw)f<g^%^o;z5w2=|Y2T+6$P-(Z8R-yEE)qO@}U*NO
            di?
            d8TKPrbpEHe'^|mVXJ%[`0x=gHqjPD;$y
            @9 Et9w90p"GgNgNYG&j'NOmN~cST0@EKRL"[sJePhE@l[,P/b'x: @)'|m?#{Coc/D@!RV[
            -&,zl_i';:crEl
            #<`5gRXLUj" =78@L=Cp
            Rz0"=z8G7l5jqvAK!T\rz{MbOyg(302h
            2024-03-29 09:25:49 UTC8151INData Raw: 31 d7 75 4f 40 0e 80 4f 29 b0 07 c0 be cc 0f a6 ba 75 0f f7 17 53 56 b5 3a 76 31 e7 c3 ec c2 22 a3 d6 36 21 02 d8 63 75 a3 ca 76 fb fe bd 81 5b b4 a5 d0 12 db 62 c9 fd 00 be a5 20 11 6c 1e 21 e6 09 d8 91 71 20 a5 83 af 8d f0 57 84 00 d0 21 ae 47 f2 24 02 32 c3 fc db da c8 43 4e 04 6c 49 dd ba a2 1b a7 08 5c 92 ba 0e fb 87 52 70 16 26 11 22 40 c5 95 7a e5 cb d7 fb ee 9d 49 6e 1d 4c 59 62 da 4f 69 04 a0 19 80 9a 00 e2 00 c4 11 90 38 d3 df 55 cd 95 d4 64 9a 04 20 87 80 5c 06 70 9c 00 47 20 6f d7 7b 04 20 c7 32 3e 98 ea f0 0e 87 ce 50 b7 c3 dc 2e 37 8a 4b 36 41 f5 49 5a d0 8b 00 45 64 c7 44 40 98 81 fc ef fc c7 2f 3d a8 53 04 05 31 2d 96 94 21 f2 56 d3 0d d8 7c dd 2d 02 94 b6 b2 a1 7e 25 02 7a 65 1c 48 59 ef 6b 23 fc 11 21 00 38 c4 f5 48 6e 0c 79 a1 9f 70 5e
            Data Ascii: 1uO@O)uSV:v1"6!cuv[b l!q W!G$2CNlI\Rp&"@zInLYbOi8Ud \pG o{ 2>P.7K6AIZEdD@/=S1-!V|-~%zeHYk#!8Hnyp^
            2024-03-29 09:25:49 UTC8192INData Raw: 12 79 ab db d3 12 c5 ef b1 91 65 3f 7b ae e1 bd fb a7 be f4 b2 db 5c 83 09 c9 9d 8c 00 79 02 40 37 00 2f 10 90 68 75 1c 0f 88 00 09 c0 7e 00 6b 09 c8 87 69 1b 37 ba 6d 3b da 7e 93 67 d5 fd f8 cc bf 7f 40 31 f8 07 9c 08 28 04 d0 e1 fc e6 95 4e 6f 72 e4 29 26 ce 5a 5b e5 9d 3f ff 1c 03 a0 33 a5 a8 0d 8b f9 36 06 02 6e 48 30 89 00 af 78 02 40 80 53 15 8c c6 c7 4f 6c 9f ec d2 27 75 ce f2 42 ff 37 5e ff 31 fb 8a 62 49 5f 77 89 00 02 52 d0 e7 8e 9b 1e 9d 35 b3 d3 2f a5 b7 54 26 b6 d5 82 48 00 cf 03 e8 4d 81 a7 60 5a a4 c9 c3 9e 80 4b 00 36 03 e4 ad ac 4f 5e fe bd 74 25 50 32 63 ca 3e c3 d2 9f 4e 3e 09 a0 19 a1 68 0c a0 1e 40 62 20 7b 65 8c 54 2e 9f 81 c8 f3 0c f2 00 5c 23 c0 65 00 c7 8c 04 1f 0d 7a f0 a6 9d 53 66 b4 cc 75 a7 4d be 24 a0 05 40 97 09 23 0c 59 d7
            Data Ascii: ye?{\y@7/hu~ki7m;~g@1(Nor)&Z[?36nH0x@SOl'uB7^1bI_wR5/T&HM`ZK6O^t%P2c>N>h@b {eT.\#ezSfuM$@#Y


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449742162.241.248.144432128C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-03-29 09:25:50 UTC349OUTGET /favicon.ico HTTP/1.1
            Host: siliconeer.com
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-03-29 09:25:50 UTC345INHTTP/1.1 200 OK
            Date: Fri, 29 Mar 2024 09:25:50 GMT
            Server: nginx/1.21.6
            Content-Type: image/x-icon
            Content-Length: 70075
            Last-Modified: Sun, 25 Apr 2021 23:32:15 GMT
            Cache-Control: max-age=604800
            Expires: Sat, 30 Mar 2024 23:48:41 GMT
            host-header: d3AuYmx1ZWhvc3QuY29t
            X-Server-Cache: true
            X-Proxy-Cache: HIT
            Accept-Ranges: bytes
            2024-03-29 09:25:50 UTC7847INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 06 00 00 00 f4 78 d4 fa 00 00 01 1b 69 54 58 74 58 4d 4c 3a 63 6f 6d 2e 61 64 6f 62 65 2e 78 6d 70 00 00 00 00 00 3c 3f 78 70 61 63 6b 65 74 20 62 65 67 69 6e 3d 22 ef bb bf 22 20 69 64 3d 22 57 35 4d 30 4d 70 43 65 68 69 48 7a 72 65 53 7a 4e 54 63 7a 6b 63 39 64 22 3f 3e 0a 3c 78 3a 78 6d 70 6d 65 74 61 20 78 6d 6c 6e 73 3a 78 3d 22 61 64 6f 62 65 3a 6e 73 3a 6d 65 74 61 2f 22 20 78 3a 78 6d 70 74 6b 3d 22 58 4d 50 20 43 6f 72 65 20 35 2e 35 2e 30 22 3e 0a 20 3c 72 64 66 3a 52 44 46 20 78 6d 6c 6e 73 3a 72 64 66 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 30 32 2f 32 32 2d 72 64 66 2d 73 79 6e 74 61 78 2d 6e 73 23 22 3e 0a 20 20 3c 72 64 66 3a 44 65
            Data Ascii: PNGIHDRxiTXtXML:com.adobe.xmp<?xpacket begin="" id="W5M0MpCehiHzreSzNTczkc9d"?><x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0"> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:De
            2024-03-29 09:25:51 UTC8151INData Raw: 31 d7 75 4f 40 0e 80 4f 29 b0 07 c0 be cc 0f a6 ba 75 0f f7 17 53 56 b5 3a 76 31 e7 c3 ec c2 22 a3 d6 36 21 02 d8 63 75 a3 ca 76 fb fe bd 81 5b b4 a5 d0 12 db 62 c9 fd 00 be a5 20 11 6c 1e 21 e6 09 d8 91 71 20 a5 83 af 8d f0 57 84 00 d0 21 ae 47 f2 24 02 32 c3 fc db da c8 43 4e 04 6c 49 dd ba a2 1b a7 08 5c 92 ba 0e fb 87 52 70 16 26 11 22 40 c5 95 7a e5 cb d7 fb ee 9d 49 6e 1d 4c 59 62 da 4f 69 04 a0 19 80 9a 00 e2 00 c4 11 90 38 d3 df 55 cd 95 d4 64 9a 04 20 87 80 5c 06 70 9c 00 47 20 6f d7 7b 04 20 c7 32 3e 98 ea f0 0e 87 ce 50 b7 c3 dc 2e 37 8a 4b 36 41 f5 49 5a d0 8b 00 45 64 c7 44 40 98 81 fc ef fc c7 2f 3d a8 53 04 05 31 2d 96 94 21 f2 56 d3 0d d8 7c dd 2d 02 94 b6 b2 a1 7e 25 02 7a 65 1c 48 59 ef 6b 23 fc 11 21 00 38 c4 f5 48 6e 0c 79 a1 9f 70 5e
            Data Ascii: 1uO@O)uSV:v1"6!cuv[b l!q W!G$2CNlI\Rp&"@zInLYbOi8Ud \pG o{ 2>P.7K6AIZEdD@/=S1-!V|-~%zeHYk#!8Hnyp^
            2024-03-29 09:25:51 UTC8192INData Raw: 12 79 ab db d3 12 c5 ef b1 91 65 3f 7b ae e1 bd fb a7 be f4 b2 db 5c 83 09 c9 9d 8c 00 79 02 40 37 00 2f 10 90 68 75 1c 0f 88 00 09 c0 7e 00 6b 09 c8 87 69 1b 37 ba 6d 3b da 7e 93 67 d5 fd f8 cc bf 7f 40 31 f8 07 9c 08 28 04 d0 e1 fc e6 95 4e 6f 72 e4 29 26 ce 5a 5b e5 9d 3f ff 1c 03 a0 33 a5 a8 0d 8b f9 36 06 02 6e 48 30 89 00 af 78 02 40 80 53 15 8c c6 c7 4f 6c 9f ec d2 27 75 ce f2 42 ff 37 5e ff 31 fb 8a 62 49 5f 77 89 00 02 52 d0 e7 8e 9b 1e 9d 35 b3 d3 2f a5 b7 54 26 b6 d5 82 48 00 cf 03 e8 4d 81 a7 60 5a a4 c9 c3 9e 80 4b 00 36 03 e4 ad ac 4f 5e fe bd 74 25 50 32 63 ca 3e c3 d2 9f 4e 3e 09 a0 19 a1 68 0c a0 1e 40 62 20 7b 65 8c 54 2e 9f 81 c8 f3 0c f2 00 5c 23 c0 65 00 c7 8c 04 1f 0d 7a f0 a6 9d 53 66 b4 cc 75 a7 4d be 24 a0 05 40 97 09 23 0c 59 d7
            Data Ascii: ye?{\y@7/hu~ki7m;~g@1(Nor)&Z[?36nH0x@SOl'uB7^1bI_wR5/T&HM`ZK6O^t%P2c>N>h@b {eT.\#ezSfuM$@#Y
            2024-03-29 09:25:51 UTC8192INData Raw: b5 be 28 66 b8 9c f5 a4 91 fe b3 9d 97 08 d2 d6 51 11 ed b6 2c 19 7e 5f 36 69 13 38 92 76 ef 20 00 15 ab 5d 29 25 02 f8 90 7e 4e 6d 21 02 fc 55 aa 8c ee b5 62 9b 32 a9 98 c0 9e 2b c9 47 1f 15 14 86 09 f9 58 2a 02 f8 4c ed 20 02 18 e5 d8 54 04 f0 f2 f2 63 63 02 7c 2d 7e 3d 58 54 d8 73 19 e0 19 80 7f c1 8b ee 09 90 4e e3 ea 9e 00 2e 87 e2 b0 44 90 82 3e 62 66 b4 1e f7 f5 56 c4 5c b4 b0 bf 27 80 57 8e cf 37 97 2e 7c 62 82 bf db a1 47 fc 22 15 80 e7 1c 71 80 50 80 4a b5 e4 93 e5 23 0f 5a cf 5e 8c 88 ce 89 73 01 c4 1a fb 12 a3 3d 23 3f 31 2f 17 f2 04 14 d6 2d 19 dc 74 d1 dc 1e 16 6f f3 0b 00 e5 db cf 5b 01 a0 a1 30 dc 1a 4f 80 30 9d 4d 45 00 e3 be 38 c2 13 a0 a6 f4 07 d8 09 f6 14 00 86 83 36 5c 56 04 68 03 b5 7f 3c 22 80 cf 99 03 6b 44 80 86 d2 87 cc 4c 56 42
            Data Ascii: (fQ,~_6i8v ])%~Nm!Ub2+GX*L Tcc|-~=XTsN.D>bfV\'W7.|bG"qPJ#Z^s=#?1/-to[0O0ME86\Vh<"kDLVB
            2024-03-29 09:25:51 UTC8192INData Raw: cf da cf 44 53 e0 47 7d 98 12 22 c0 85 5e 07 64 54 0c 0a aa f1 e3 da 39 36 19 fc eb f6 1a 5d ff bf ac 27 07 00 a8 cc b5 11 17 15 01 4f 1a 95 0c 7b 6e de b4 38 59 3b 24 ce 98 f3 89 ef b9 cc cc df 54 a0 3e 62 be c6 fe 87 25 02 5c ed 75 40 6c 50 c0 d7 87 b7 c5 5b 75 72 64 d4 bb 73 9a 10 ed e0 df 90 1f e3 92 22 40 45 40 a7 02 38 18 de 76 49 04 93 84 19 c8 16 00 31 71 4d 9e 03 70 82 ea b6 45 55 31 2e 12 f7 9b 0b 89 80 5a 00 4e 46 c7 b5 6a 2a 4a 60 06 73 e2 27 6b 3e 6c d8 b2 11 b4 93 34 24 6d 4b d8 05 e0 39 3b 80 65 cf 5c 07 af c7 a3 82 fc b2 eb 4e 1f 3b 2c 99 c0 ce 58 30 21 be 30 75 fb d6 d7 82 bd bc c6 42 e7 d1 73 5d 4f 80 30 ce a4 08 78 14 1b 14 54 e3 e8 86 85 36 39 6c e5 f9 7e 09 e5 1f 15 14 9c 04 e0 63 1c a0 b9 1c 5d 54 04 18 b9 aa 1b 84 86 bc f0 ed ba 04
            Data Ascii: DSG}"^dT96]'O{n8Y;$T>b%\u@lP[urds"@E@8vI1qMpEU1.ZNFj*J`s'k>l4$mK9;e\N;,X0!0uBs]O0xT69l~c]T
            2024-03-29 09:25:51 UTC8192INData Raw: 0b c6 54 4a cd c9 6c c1 2a 51 cb 55 be 08 e0 c6 9b 82 c7 13 60 bd 08 e0 72 50 58 04 64 87 78 fb 34 fc 75 f5 86 83 12 44 14 c1 1b c3 87 37 8c ea d5 e3 4a fb d1 63 bb d9 d2 8e ad b0 63 c1 d4 ac 94 1d 1b bb 94 f2 f1 8d 0d f6 f2 3e ae 84 08 88 f6 0f 18 f7 fd aa b9 47 ac e5 f4 e9 bf 7f ef 00 10 cb 67 e0 11 01 22 26 0a 2e 11 bc 92 9d dd d3 74 29 4c 4c 00 70 cb 1e 22 80 0b 27 f7 04 7c 95 fe f5 84 1f 59 a9 98 02 20 6d cb f9 7c 00 1f 80 52 a3 ab ac 78 7b 02 32 01 da 25 39 e9 84 ac 5f ff 7b 2f 9e dc 06 80 b0 de c7 18 b9 2a 23 02 dc 7e 62 a0 8b 2f 11 0c f0 f2 4e 7f 3e a2 5c e5 8b 9b 3e b1 6a d9 99 a5 78 67 d4 a8 8e 67 32 1e 9c 02 50 f5 b7 7b 29 9f 46 f5 ea 71 a1 cb d8 71 35 6d 69 d3 56 38 9b b4 fa f6 e5 ad 6b 5f 6c 1e 55 ae 31 40 2f 03 56 8b 80 7d a7 36 2d b3 6a 9b
            Data Ascii: TJl*QU`rPXdx4uD7Jcc>Gg"&.t)LLp"'|Y m|Rx{2%9_{/*#~b/N>\>jxgg2P{)Fqq5miV8k_lU1@/V}6-j
            2024-03-29 09:25:51 UTC8192INData Raw: 03 83 40 09 d0 64 62 20 e3 87 89 eb fd e3 a7 e6 72 0b f3 13 b4 1e 02 68 a9 24 62 39 27 01 ea a9 d6 9c 30 22 01 91 b7 44 d0 52 af 7c c5 de c7 d7 7e 35 5d 1e 90 6f 70 f3 e0 47 de 04 b0 1c f6 7a ef a4 41 f4 35 09 08 c0 12 41 01 1a 91 80 0b 3d 1a b6 f4 9a bc bd 75 68 df 87 00 64 3b f4 b9 46 02 38 cf 1f 9f 04 14 dd 91 92 36 24 7b e3 fa 66 87 4c 6b 72 bc 8d 59 0d 0f 8e 9c 50 eb c8 d5 82 e7 a5 9d 37 1b 91 4e 02 38 e5 71 73 c2 89 04 f0 da 12 74 e6 16 e4 27 68 46 00 1a 3d db f4 3e 58 d7 da c2 33 12 40 99 bf e4 d5 d3 91 13 66 24 20 8c 27 06 32 f9 85 95 e2 12 6e ff ee b5 6d 7e 59 e6 37 63 e9 fc d8 9b 07 3f b2 e7 62 49 d1 40 f9 35 61 6b 8f 38 66 36 56 7d 62 a0 53 12 40 9b 56 4c 79 60 e1 c4 17 4a 15 02 73 09 9d 47 8e e8 03 a0 8b b3 4f 41 3b 27 01 92 e7 58 4c 02 be 7d
            Data Ascii: @db rh$b9'0"DR|~5]opGzA5A=uhd;F86${fLkrYP7N8qst'hF=>X3@f$ '2nm~Y7c?bI@5ak8f6V}bS@VLy`JsGOA;'XL}
            2024-03-29 09:25:51 UTC8192INData Raw: 12 60 e9 5c bd d6 1d 1b e6 4d f7 ea 53 bd 69 7d 06 10 4a 49 6f 00 b3 09 90 61 2f d3 45 25 4c 03 12 20 d8 be 0f 60 64 f6 db 2b 7c a2 74 44 3a 74 02 e0 25 2a f7 af 6f 20 04 63 01 cc 01 10 cb 63 f6 41 a4 04 08 7f af 04 30 2e cf 74 c0 ab 37 c3 6a 03 5a 2f 02 30 36 18 26 06 02 81 57 02 82 8c 04 98 5b 57 ae 56 69 fb 82 35 9a 7c d9 ed c9 09 c3 53 7f 39 93 fd 2e ac b3 c2 45 11 49 a1 93 00 79 1a ef 99 75 81 04 d0 e4 e8 98 9e 7f 9b de 7c 97 5b a0 8b 48 eb 33 20 0d 80 09 c0 7d f2 2d 84 e5 f7 80 8d 5b 1c b5 06 24 c0 6a 77 09 c0 73 d9 6f af 58 cf 39 1d 1d 6e 40 27 00 5e 20 c5 58 af 06 a5 64 03 80 7b d8 7e cc 27 24 c0 bf 4a 00 00 1c 05 d0 2f cf 74 e0 47 e9 79 b9 83 6a 03 5a 1f 04 70 33 97 04 58 83 b4 86 ad 93 00 45 3b 7f 90 80 38 43 d4 d7 c7 d6 ee e8 cc 75 e2 43 8c 5d
            Data Ascii: `\MSi}JIoa/E%L `d+|tD:t%*o ccA0.t7jZ/06&W[WVi5|S9.EIyu|[H3 }-[$jwsoX9n@'^ Xd{~'$J/tGyjZp3XE;8CuC]
            2024-03-29 09:25:51 UTC4925INData Raw: f6 f8 b1 dc 1b d7 6a 2b f8 94 c5 ac 64 13 86 3b 06 9a b3 37 bc 1f ad 70 b0 db 48 eb db fd 6e 00 b3 01 72 b7 5a 6c 16 95 3c 00 be dc 27 e0 1a 80 57 01 b2 f0 f4 a6 8d 97 5d 3c 0d 1d 2e 40 57 00 7c 8c 7c 53 d6 39 db 72 c1 3a 00 16 c1 fa 55 b5 40 e0 02 80 57 41 70 73 fe fa ac a7 7d d5 f9 03 c0 37 47 7f 7a da f1 97 f2 9b 3c 9b 1a 21 c3 01 e6 2a 89 15 1e 92 39 56 41 ba f1 96 3a 04 f4 43 00 71 7c 85 24 2c 95 80 2a 00 3e 4d 33 76 4c 96 19 a8 20 29 ae cc 58 5e ba 3e 1c 80 a8 d6 cf 66 36 53 38 d8 6d e4 6e dc fa 5d ee c6 ad ed 61 5d ce f9 39 00 73 80 94 80 2c 03 30 03 40 9d d3 9b 36 4d d1 3b 7f df 43 57 00 fc 8c 14 63 46 14 ac 1f 69 e9 0f e0 51 88 de f2 7c 0e 0b 80 dd 00 d6 00 d8 96 6f ca f2 cb 67 5c 53 8c 75 df 03 d0 8d ff ce 1e da 4a 80 37 5f 11 4c 8a 8d 7f e5 d0
            Data Ascii: j+d;7pHnrZl<'W]<.@W||S9r:U@WAps}7Gz<!*9VA:Cq|$,*>M3vL )X^>f6S8mn]a]9s,0@6M;CWcFiQ|og\SuJ7_L


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44974323.33.180.114443
            TimestampBytes transferredDirectionData
            2024-03-29 09:25:51 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-29 09:25:51 UTC511INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=164238
            Date: Fri, 29 Mar 2024 09:25:51 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974423.33.180.114443
            TimestampBytes transferredDirectionData
            2024-03-29 09:25:51 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-03-29 09:25:51 UTC531INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=164238
            Date: Fri, 29 Mar 2024 09:25:51 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-03-29 09:25:51 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:10:25:41
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:10:25:44
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1936,i,10283009642975068563,18317178896216016107,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:10:25:46
            Start date:29/03/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://siliconeer.com/current/wp-content/uploads/2020/07/harsh-chhaya-i-have-nothing-against-working-in-a-tv-show.jpg"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly