Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==

Overview

General Information

Sample URL:https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==
Analysis ID:1426997
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3448 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2444,i,11004403337077409759,7609749337395893540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ== HTTP/1.1Host: t5.emails.virginatlantic.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: t5.emails.virginatlantic.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@20/0@19/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2444,i,11004403337077409759,7609749337395893540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ=="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2444,i,11004403337077409759,7609749337395893540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.217.174
truefalse
    high
    www.google.com
    142.250.105.106
    truefalse
      high
      virginatlantic-mid-prod5-alb-1704172162.eu-west-1.elb.amazonaws.com
      52.19.118.92
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          t5.emails.virginatlantic.com
          unknown
          unknownfalse
            high
            magairports.btuijkoi.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==false
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.105.106
                www.google.comUnited States
                15169GOOGLEUSfalse
                52.19.118.92
                virginatlantic-mid-prod5-alb-1704172162.eu-west-1.elb.amazonaws.comUnited States
                16509AMAZON-02USfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1426997
                Start date and time:2024-04-16 21:22:26 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 9s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:9
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@20/0@19/4
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.251.15.94, 172.253.124.100, 172.253.124.139, 172.253.124.101, 172.253.124.138, 172.253.124.102, 172.253.124.113, 74.125.136.84, 34.104.35.123, 20.114.59.183, 23.40.205.66, 23.40.205.74, 23.40.205.59, 23.40.205.75, 23.40.205.67, 192.229.211.108, 52.165.164.15, 20.3.187.198, 108.177.122.94
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, virginatlantic-mid-prod5-lb.campaign.adobe.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 16, 2024 21:23:11.111469030 CEST49675443192.168.2.4173.222.162.32
                Apr 16, 2024 21:23:19.262403965 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.262487888 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.262577057 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.263012886 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.263089895 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.263202906 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.263241053 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.263325930 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.263652086 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.263721943 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.910096884 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.912543058 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.912606955 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.913512945 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.913608074 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.915494919 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.915558100 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.916157007 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.916174889 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.924180031 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.924717903 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.924778938 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.926279068 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.926500082 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.930337906 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.930505037 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:19.970298052 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.984776020 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:19.984812975 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:23:20.033577919 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:20.130800962 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:20.130882025 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:20.131145000 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:20.132302046 CEST49735443192.168.2.452.19.118.92
                Apr 16, 2024 21:23:20.132344961 CEST4434973552.19.118.92192.168.2.4
                Apr 16, 2024 21:23:20.719835997 CEST49675443192.168.2.4173.222.162.32
                Apr 16, 2024 21:23:21.448132992 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:21.448214054 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:21.448314905 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:21.448807955 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:21.448844910 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:21.666950941 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:21.667574883 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:21.667634964 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:21.668576956 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:21.668674946 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:22.155725956 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:22.155891895 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:22.203617096 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:22.203674078 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:22.250611067 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:22.731708050 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:22.731789112 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:22.731888056 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:22.733997107 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:22.734030962 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:22.960335016 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:22.960535049 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:22.965285063 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:22.965313911 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:22.965725899 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.016293049 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.019843102 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.060156107 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.161227942 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.161391973 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.161580086 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.161672115 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.161715984 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.161751032 CEST49740443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.161766052 CEST4434974023.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.213193893 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.213224888 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.213541985 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.214001894 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.214014053 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.434293985 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.434360981 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.435810089 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.435817957 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.436353922 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.437345982 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.480112076 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.643996000 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.644216061 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.644330025 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.645986080 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.645986080 CEST49741443192.168.2.423.208.128.100
                Apr 16, 2024 21:23:23.646003008 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:23.646022081 CEST4434974123.208.128.100192.168.2.4
                Apr 16, 2024 21:23:31.685089111 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:31.685141087 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:23:31.685206890 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:31.866231918 CEST49739443192.168.2.4142.250.105.106
                Apr 16, 2024 21:23:31.866277933 CEST44349739142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:05.000528097 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:24:05.000582933 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:24:21.388742924 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:21.388744116 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:24:21.388777971 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.388858080 CEST4434973652.19.118.92192.168.2.4
                Apr 16, 2024 21:24:21.388961077 CEST49736443192.168.2.452.19.118.92
                Apr 16, 2024 21:24:21.389183998 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:21.389457941 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:21.389481068 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.605963945 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.606549025 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:21.606575966 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.607027054 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.607577085 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:21.607661963 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:21.656980038 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:28.111047029 CEST4972380192.168.2.4199.232.210.172
                Apr 16, 2024 21:24:28.111287117 CEST4972480192.168.2.4199.232.210.172
                Apr 16, 2024 21:24:28.214870930 CEST8049723199.232.210.172192.168.2.4
                Apr 16, 2024 21:24:28.214920998 CEST8049724199.232.210.172192.168.2.4
                Apr 16, 2024 21:24:28.214953899 CEST8049723199.232.210.172192.168.2.4
                Apr 16, 2024 21:24:28.215121984 CEST4972380192.168.2.4199.232.210.172
                Apr 16, 2024 21:24:28.216928959 CEST8049724199.232.210.172192.168.2.4
                Apr 16, 2024 21:24:28.217103958 CEST4972480192.168.2.4199.232.210.172
                Apr 16, 2024 21:24:31.648473024 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:31.648528099 CEST44349749142.250.105.106192.168.2.4
                Apr 16, 2024 21:24:31.648622990 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:31.856122017 CEST49749443192.168.2.4142.250.105.106
                Apr 16, 2024 21:24:31.856137991 CEST44349749142.250.105.106192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 16, 2024 21:23:17.414797068 CEST53583471.1.1.1192.168.2.4
                Apr 16, 2024 21:23:17.496609926 CEST53604631.1.1.1192.168.2.4
                Apr 16, 2024 21:23:18.120914936 CEST53540591.1.1.1192.168.2.4
                Apr 16, 2024 21:23:19.116735935 CEST6273753192.168.2.41.1.1.1
                Apr 16, 2024 21:23:19.116913080 CEST5521753192.168.2.41.1.1.1
                Apr 16, 2024 21:23:20.139419079 CEST5950953192.168.2.41.1.1.1
                Apr 16, 2024 21:23:20.139842033 CEST5487753192.168.2.41.1.1.1
                Apr 16, 2024 21:23:20.247528076 CEST53595091.1.1.1192.168.2.4
                Apr 16, 2024 21:23:20.261095047 CEST53548771.1.1.1192.168.2.4
                Apr 16, 2024 21:23:20.262799978 CEST6066253192.168.2.41.1.1.1
                Apr 16, 2024 21:23:20.383395910 CEST53606621.1.1.1192.168.2.4
                Apr 16, 2024 21:23:20.538079977 CEST5955553192.168.2.48.8.8.8
                Apr 16, 2024 21:23:20.565406084 CEST6396053192.168.2.41.1.1.1
                Apr 16, 2024 21:23:20.644383907 CEST53595558.8.8.8192.168.2.4
                Apr 16, 2024 21:23:20.670372009 CEST53639601.1.1.1192.168.2.4
                Apr 16, 2024 21:23:21.340576887 CEST5895053192.168.2.41.1.1.1
                Apr 16, 2024 21:23:21.340847015 CEST4936553192.168.2.41.1.1.1
                Apr 16, 2024 21:23:21.446029902 CEST53493651.1.1.1192.168.2.4
                Apr 16, 2024 21:23:21.446753979 CEST53589501.1.1.1192.168.2.4
                Apr 16, 2024 21:23:21.573750019 CEST5092453192.168.2.41.1.1.1
                Apr 16, 2024 21:23:21.574337959 CEST6232453192.168.2.41.1.1.1
                Apr 16, 2024 21:23:21.683331966 CEST53509241.1.1.1192.168.2.4
                Apr 16, 2024 21:23:21.696608067 CEST53623241.1.1.1192.168.2.4
                Apr 16, 2024 21:23:27.136054993 CEST5113853192.168.2.41.1.1.1
                Apr 16, 2024 21:23:27.136327028 CEST5841553192.168.2.41.1.1.1
                Apr 16, 2024 21:23:27.244317055 CEST53584151.1.1.1192.168.2.4
                Apr 16, 2024 21:23:27.260716915 CEST53511381.1.1.1192.168.2.4
                Apr 16, 2024 21:23:27.261424065 CEST6043453192.168.2.41.1.1.1
                Apr 16, 2024 21:23:27.370048046 CEST53604341.1.1.1192.168.2.4
                Apr 16, 2024 21:23:36.608334064 CEST53499781.1.1.1192.168.2.4
                Apr 16, 2024 21:23:39.719578981 CEST138138192.168.2.4192.168.2.255
                Apr 16, 2024 21:23:55.351011038 CEST53563731.1.1.1192.168.2.4
                Apr 16, 2024 21:23:57.390245914 CEST5486353192.168.2.41.1.1.1
                Apr 16, 2024 21:23:57.390466928 CEST5818253192.168.2.41.1.1.1
                Apr 16, 2024 21:23:57.499260902 CEST53548631.1.1.1192.168.2.4
                Apr 16, 2024 21:23:57.512140036 CEST53581821.1.1.1192.168.2.4
                Apr 16, 2024 21:23:57.514202118 CEST5385453192.168.2.41.1.1.1
                Apr 16, 2024 21:23:57.625852108 CEST53538541.1.1.1192.168.2.4
                Apr 16, 2024 21:24:10.345016003 CEST5085653192.168.2.41.1.1.1
                Apr 16, 2024 21:24:10.453375101 CEST53508561.1.1.1192.168.2.4
                Apr 16, 2024 21:24:16.980017900 CEST53531421.1.1.1192.168.2.4
                Apr 16, 2024 21:24:17.978446007 CEST53579671.1.1.1192.168.2.4
                Apr 16, 2024 21:24:29.612792969 CEST6493153192.168.2.41.1.1.1
                Apr 16, 2024 21:24:29.733793974 CEST53649311.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 16, 2024 21:23:19.116735935 CEST192.168.2.41.1.1.10xabfStandard query (0)t5.emails.virginatlantic.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:19.116913080 CEST192.168.2.41.1.1.10xdff9Standard query (0)t5.emails.virginatlantic.com65IN (0x0001)false
                Apr 16, 2024 21:23:20.139419079 CEST192.168.2.41.1.1.10xd453Standard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.139842033 CEST192.168.2.41.1.1.10xcb1aStandard query (0)magairports.btuijkoi.com65IN (0x0001)false
                Apr 16, 2024 21:23:20.262799978 CEST192.168.2.41.1.1.10x5caeStandard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.538079977 CEST192.168.2.48.8.8.80x5c85Standard query (0)google.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.565406084 CEST192.168.2.41.1.1.10x628cStandard query (0)google.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.340576887 CEST192.168.2.41.1.1.10x13f5Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.340847015 CEST192.168.2.41.1.1.10x6eeaStandard query (0)www.google.com65IN (0x0001)false
                Apr 16, 2024 21:23:21.573750019 CEST192.168.2.41.1.1.10x7065Standard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.574337959 CEST192.168.2.41.1.1.10xfac3Standard query (0)magairports.btuijkoi.com65IN (0x0001)false
                Apr 16, 2024 21:23:27.136054993 CEST192.168.2.41.1.1.10x1bStandard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:27.136327028 CEST192.168.2.41.1.1.10xf796Standard query (0)magairports.btuijkoi.com65IN (0x0001)false
                Apr 16, 2024 21:23:27.261424065 CEST192.168.2.41.1.1.10xe46dStandard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:57.390245914 CEST192.168.2.41.1.1.10xf3eaStandard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:57.390466928 CEST192.168.2.41.1.1.10xf11eStandard query (0)magairports.btuijkoi.com65IN (0x0001)false
                Apr 16, 2024 21:23:57.514202118 CEST192.168.2.41.1.1.10x5fd6Standard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:24:10.345016003 CEST192.168.2.41.1.1.10x3a10Standard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                Apr 16, 2024 21:24:29.612792969 CEST192.168.2.41.1.1.10xa41Standard query (0)magairports.btuijkoi.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 16, 2024 21:23:19.240871906 CEST1.1.1.1192.168.2.40xdff9No error (0)t5.emails.virginatlantic.comvirginatlantic-mid-prod5-lb.campaign.adobe.comCNAME (Canonical name)IN (0x0001)false
                Apr 16, 2024 21:23:19.261591911 CEST1.1.1.1192.168.2.40xabfNo error (0)t5.emails.virginatlantic.comvirginatlantic-mid-prod5-lb.campaign.adobe.comCNAME (Canonical name)IN (0x0001)false
                Apr 16, 2024 21:23:19.261591911 CEST1.1.1.1192.168.2.40xabfNo error (0)virginatlantic-mid-prod5-alb-1704172162.eu-west-1.elb.amazonaws.com52.19.118.92A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:19.261591911 CEST1.1.1.1192.168.2.40xabfNo error (0)virginatlantic-mid-prod5-alb-1704172162.eu-west-1.elb.amazonaws.com52.31.142.231A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.247528076 CEST1.1.1.1192.168.2.40xd453Name error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.261095047 CEST1.1.1.1192.168.2.40xcb1aName error (3)magairports.btuijkoi.comnonenone65IN (0x0001)false
                Apr 16, 2024 21:23:20.383395910 CEST1.1.1.1192.168.2.40x5caeName error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.644383907 CEST8.8.8.8192.168.2.40x5c85No error (0)google.com142.250.217.174A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.101A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.102A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.100A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.139A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.113A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:20.670372009 CEST1.1.1.1192.168.2.40x628cNo error (0)google.com172.217.215.138A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446029902 CEST1.1.1.1192.168.2.40x6eeaNo error (0)www.google.com65IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.446753979 CEST1.1.1.1192.168.2.40x13f5No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.683331966 CEST1.1.1.1192.168.2.40x7065Name error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:21.696608067 CEST1.1.1.1192.168.2.40xfac3Name error (3)magairports.btuijkoi.comnonenone65IN (0x0001)false
                Apr 16, 2024 21:23:27.244317055 CEST1.1.1.1192.168.2.40xf796Name error (3)magairports.btuijkoi.comnonenone65IN (0x0001)false
                Apr 16, 2024 21:23:27.260716915 CEST1.1.1.1192.168.2.40x1bName error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:27.370048046 CEST1.1.1.1192.168.2.40xe46dName error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:35.201841116 CEST1.1.1.1192.168.2.40x8600No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 16, 2024 21:23:35.201841116 CEST1.1.1.1192.168.2.40x8600No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:47.637979031 CEST1.1.1.1192.168.2.40xe6ebNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 16, 2024 21:23:47.637979031 CEST1.1.1.1192.168.2.40xe6ebNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:57.499260902 CEST1.1.1.1192.168.2.40xf3eaName error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:23:57.512140036 CEST1.1.1.1192.168.2.40xf11eName error (3)magairports.btuijkoi.comnonenone65IN (0x0001)false
                Apr 16, 2024 21:23:57.625852108 CEST1.1.1.1192.168.2.40x5fd6Name error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:24:10.453375101 CEST1.1.1.1192.168.2.40x3a10Name error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                Apr 16, 2024 21:24:29.733793974 CEST1.1.1.1192.168.2.40xa41Name error (3)magairports.btuijkoi.comnonenoneA (IP address)IN (0x0001)false
                • t5.emails.virginatlantic.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44973552.19.118.924435900C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-16 19:23:19 UTC773OUTGET /r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ== HTTP/1.1
                Host: t5.emails.virginatlantic.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-16 19:23:20 UTC679INHTTP/1.1 302 Found
                Date: Tue, 16 Apr 2024 19:23:20 GMT
                Content-Type: text/plain; charset=utf-8
                Content-Length: 17
                Connection: close
                Server: Apache
                X-Robots-Tag: noindex
                P3P: CP="CAO DSP COR CURa DEVa TAIa OUR BUS IND UNI COM NAV"
                Location: https://Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ==
                Set-Cookie: AMCV_30516EBF55FC098E7F000101%40AdobeOrg=MCMID%7C46704646165246760913147945495909892095; Domain=virginatlantic.com; Path=/; Expires=Sun, 11-May-2025 19:23:20 GMT
                Set-Cookie: nlid=1156f0e5|23add98e; Domain=virginatlantic.com; Path=/
                Set-Cookie: nllastdelid=23add98e; Domain=virginatlantic.com; Path=/; Expires=Sun, 11-May-2025 19:23:20 GMT
                2024-04-16 19:23:20 UTC17INData Raw: 54 65 6d 70 6f 72 61 72 69 6c 79 20 6d 6f 76 65 64
                Data Ascii: Temporarily moved


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44974023.208.128.100443
                TimestampBytes transferredDirectionData
                2024-04-16 19:23:23 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-16 19:23:23 UTC468INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus2-z1
                Cache-Control: public, max-age=128466
                Date: Tue, 16 Apr 2024 19:23:23 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974123.208.128.100443
                TimestampBytes transferredDirectionData
                2024-04-16 19:23:23 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-16 19:23:23 UTC531INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=128475
                Date: Tue, 16 Apr 2024 19:23:23 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-16 19:23:23 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:21:23:13
                Start date:16/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:21:23:15
                Start date:16/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2444,i,11004403337077409759,7609749337395893540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:21:23:18
                Start date:16/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t5.emails.virginatlantic.com/r/?id=h1156f0e5,23add98e,23ade7cf&p1=Magairports.btuijkoi.com/Z2FycnkuYmFybG93QG1hZ2FpcnBvcnRzLmNvbQ=="
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly