Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6f

Overview

General Information

Sample URL:https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjV
Analysis ID:1427107
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Drops files with a non-matching file extension (content does not match file extension)

Classification

  • System is w10x64
  • chrome.exe (PID: 2500 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1984,i,9554475306055727456,10145289589561791208,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approvedHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX- HTTP/1.1Host: email.notifications.joinhandshake.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved HTTP/1.1Host: content-calpoly-edu.s3.amazonaws.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: content-calpoly-edu.s3.amazonaws.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approvedAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: email.notifications.joinhandshake.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 Forbiddenx-amz-request-id: XJNNKHPYFE50K4DGx-amz-id-2: U2rAKxSCPjqS6N87DLDN153EYKeyfgzWZ6p1Aa6X52HwBPM++/0jxfeR/WZYN3JioxpjA2QMmZY=Content-Type: application/xmlTransfer-Encoding: chunkedDate: Tue, 16 Apr 2024 23:50:11 GMTServer: AmazonS3Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@19/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1984,i,9554475306055727456,10145289589561791208,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1984,i,9554475306055727456,10145289589561791208,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Confirm
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: Chrome Cache Entry: 42
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: Chrome Cache Entry: 42Jump to dropped file
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    64.233.176.147
    truefalse
      high
      mailgun.org
      34.110.180.34
      truefalse
        unknown
        s3-us-west-1-w.amazonaws.com
        52.219.220.161
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            email.notifications.joinhandshake.com
            unknown
            unknownfalse
              high
              content-calpoly-edu.s3.amazonaws.com
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://content-calpoly-edu.s3.amazonaws.com/favicon.icofalse
                  high
                  https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approvedfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    34.110.180.34
                    mailgun.orgUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    52.219.220.161
                    s3-us-west-1-w.amazonaws.comUnited States
                    16509AMAZON-02USfalse
                    64.233.176.147
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1427107
                    Start date and time:2024-04-17 01:49:20 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 8s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@19/4@6/5
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.251.15.94, 172.217.215.102, 172.217.215.139, 172.217.215.101, 172.217.215.138, 172.217.215.113, 172.217.215.100, 172.253.124.84, 34.104.35.123, 52.165.165.26, 199.232.210.172, 192.229.211.108, 13.85.23.206, 20.166.126.56, 142.250.105.94
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:XML 1.0 document, ASCII text
                    Category:downloaded
                    Size (bytes):243
                    Entropy (8bit):5.638441408128923
                    Encrypted:false
                    SSDEEP:6:TMVBd/ZbZjZvKtWRVzjk1Hi+v/5dOGkX9rPR3lrowan:TMHd9BZKtWRGYoBdOGkpPDa
                    MD5:1D56057B456AB957C9083BCEA2D06CDB
                    SHA1:F847145BA6D94092982A93922A2B0D04FC8A450C
                    SHA-256:172E5071785EDB3F7B8931414611858419BFEC0DA3219D0DE823632666EE2DE0
                    SHA-512:FC8F08B7086624536A9EB7516EDED8DEDCCA94F520EC3166BE6AD9E88AB0218697FCB80DE132AB7CF0C61ED59507FC830575C0D0ACFA89EE6F3D9AB6D1814171
                    Malicious:false
                    Reputation:low
                    URL:https://content-calpoly-edu.s3.amazonaws.com/favicon.ico
                    Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>XJNNKHPYFE50K4DG</RequestId><HostId>U2rAKxSCPjqS6N87DLDN153EYKeyfgzWZ6p1Aa6X52HwBPM++/0jxfeR/WZYN3JioxpjA2QMmZY=</HostId></Error>
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:PDF document, version 1.6 (zip deflate encoded)
                    Category:downloaded
                    Size (bytes):412528
                    Entropy (8bit):7.989353238765301
                    Encrypted:false
                    SSDEEP:12288:pqq3KgSRfIahxvu9ewmNPU4HgpoHHEk3Ql:pqq3KgUb7w+PUc0oHDA
                    MD5:B80CF06A3490C75AAFC73A043F8FE12E
                    SHA1:BB8CB85FE4E5CB2647AF3C20F41D3292C4CA6459
                    SHA-256:DCDE4EFE3D5DD9B994B62A0D21079F8B70D050EF1714B64D9AE49A4A5CB0E7C8
                    SHA-512:55C2F609AFE18C9146F4A752BBF9DCF47EBE30DA2FE68C8EBF6B59608B3892F7B2B2AD454B7D424BD214B8FB4AD79C9AC9A9A192410A8CA11A7B360A2431376C
                    Malicious:false
                    Reputation:low
                    URL:https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved
                    Preview:%PDF-1.6.%......494 0 obj.<</Linearized 1/L 412528/O 496/E 237967/N 7/T 412034/H [ 534 372]>>.endobj. ..524 0 obj.<</DecodeParms<</Columns 5/Predictor 12>>/Filter/FlateDecode/ID[<17540DEDD549994B84228AB79B0727E0><33E0714FE2B931449B16A2637A75BA89>]/Index[494 54]/Info 493 0 R/Length 131/Prev 412035/Root 495 0 R/Size 548/Type/XRef/W[1 3 1]>>stream..h.bbd`.``b``....W@$.....,...-..5...`.J0...-.....O.H.>0[.L......]....".v.H.. .......b.nB.1/..~.p..3&.........k.*.......... .......endstream.endobj.startxref..0..%%EOF.. ..547 0 obj.<</C 306/Filter/FlateDecode/I 328/Length 277/O 290/S 195>>stream..h.b```..W.......B.. ..cc`a..&...........l.....?.......jF.Gg9..W.+.....N6...\aQd.e..up...s..R.!.pD.../..&."....B5@......@S8.4.9.`..D.B$L; *,:..]..U``-~..e.X..P...`.h..L..W...0.d9.p......K$.+..l.dw....v..20...>`..n.b.....p.L....7U.61....x ...&.....AJ...:.lnS .........MP..endstream.endobj.495 0 obj.<</Lang(...E.N.-.U.S)/MarkInfo<</Marked true>>/Metadata 42 0 R/Outlines 75 0 R/PageL
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 17, 2024 01:50:02.568419933 CEST49678443192.168.2.4104.46.162.224
                    Apr 17, 2024 01:50:02.615282059 CEST49675443192.168.2.4173.222.162.32
                    Apr 17, 2024 01:50:10.229620934 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.229710102 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.229780912 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.230181932 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.230268002 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.230328083 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.230422974 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.230454922 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.230688095 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.230726004 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.465400934 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.465682030 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.465702057 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.466581106 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.466638088 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.467884064 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.467936993 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.468079090 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.468086958 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.472130060 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.472387075 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.472449064 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.473942995 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.474020004 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.474946976 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.475027084 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.520132065 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.520159006 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.520212889 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.566293001 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.696515083 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.696610928 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.696674109 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.698527098 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.698575020 CEST4434973534.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:10.698606014 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.698641062 CEST49735443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:10.809211969 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:10.809267998 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:10.809336901 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:10.809587002 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:10.809603930 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.287271023 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.287529945 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.287559032 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.288644075 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.288815022 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.289805889 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.289866924 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.290023088 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.290039062 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.341495037 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.494828939 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495186090 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495198965 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495244980 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495268106 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.495271921 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495285988 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495313883 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.495336056 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.495336056 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.495349884 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.495383978 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.652028084 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.652050018 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.652124882 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.652149916 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.652178049 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.652276993 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.652313948 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.808780909 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.808804035 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.808867931 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.808900118 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.808928967 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.808960915 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.808995962 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.853519917 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.853588104 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.853694916 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.853759050 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.853759050 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.853759050 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.853791952 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.897511959 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.965534925 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965606928 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965671062 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.965698957 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965720892 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.965744019 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.965785980 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965893984 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965938091 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.965962887 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.965971947 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966002941 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966140985 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966200113 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966224909 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966232061 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966264009 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966393948 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966445923 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966474056 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966480017 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966511011 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966634035 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966682911 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966701031 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966717005 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966748953 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966921091 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966963053 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.966981888 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:11.966989040 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:11.967022896 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.010648966 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.010654926 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.010746002 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.010792971 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.010818958 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.010824919 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.010858059 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.011039972 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.011101007 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.011109114 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.011123896 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.011157036 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.052443027 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.052459002 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.072716951 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.094671011 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.094723940 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.094790936 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.095271111 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.095297098 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.122030020 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.122122049 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.122172117 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.122234106 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.123552084 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.123996019 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124036074 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124067068 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124078035 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124109983 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124300003 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124347925 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124356985 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124377012 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124409914 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124558926 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124603987 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124620914 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124627113 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124655008 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124836922 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124882936 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124891996 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.124906063 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.124932051 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125073910 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125113010 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125130892 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125137091 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125168085 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125276089 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125319958 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125329971 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125341892 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125375986 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125507116 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125547886 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125566959 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125572920 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125613928 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125713110 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125792027 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125834942 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125842094 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.125857115 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.125988007 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.126034021 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.126048088 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.126060009 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.126089096 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.126101017 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.126199007 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.126240015 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.159212112 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.167135954 CEST49737443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.167149067 CEST4434973752.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.223140001 CEST49675443192.168.2.4173.222.162.32
                    Apr 17, 2024 01:50:12.572822094 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.618778944 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.618803024 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.620405912 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.621543884 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.621839046 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.621851921 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.621957064 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.669816017 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.785470009 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.785733938 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:12.785893917 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.895802975 CEST49740443192.168.2.452.219.220.161
                    Apr 17, 2024 01:50:12.895854950 CEST4434974052.219.220.161192.168.2.4
                    Apr 17, 2024 01:50:13.450665951 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.450715065 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:13.450779915 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.455267906 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.455280066 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:13.589500904 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.589553118 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.589627981 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.623795033 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.623843908 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.675910950 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:13.676002979 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.679776907 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.679783106 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:13.680113077 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:13.726803064 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.849520922 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.853718042 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.853744984 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.855334044 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.855408907 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.881803036 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.882045031 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.929929972 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:13.929944038 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:13.962969065 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:13.976793051 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:14.008127928 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.076170921 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.076308966 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.076551914 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.079402924 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.079426050 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.079437971 CEST49741443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.079442978 CEST44349741104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.159090042 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.159166098 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.159485102 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.161834002 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.161865950 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.376840115 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.376936913 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.379367113 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.379399061 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.379748106 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.381637096 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.424159050 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.613872051 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.613991976 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.614069939 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.615073919 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.615124941 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:14.615156889 CEST49743443192.168.2.4104.123.200.136
                    Apr 17, 2024 01:50:14.615171909 CEST44349743104.123.200.136192.168.2.4
                    Apr 17, 2024 01:50:15.585963964 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:15.586157084 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:15.586333036 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:17.053894997 CEST49736443192.168.2.434.110.180.34
                    Apr 17, 2024 01:50:17.053973913 CEST4434973634.110.180.34192.168.2.4
                    Apr 17, 2024 01:50:23.838078022 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:23.838254929 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:50:23.838614941 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:25.055385113 CEST49742443192.168.2.464.233.176.147
                    Apr 17, 2024 01:50:25.055408955 CEST4434974264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.485682011 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:13.485734940 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.485794067 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:13.486335993 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:13.486356974 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.705573082 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.706471920 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:13.706509113 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.706969976 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.707804918 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:13.707899094 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:13.754620075 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:21.520453930 CEST4972480192.168.2.472.21.81.240
                    Apr 17, 2024 01:51:21.520453930 CEST4972380192.168.2.472.21.81.240
                    Apr 17, 2024 01:51:21.624471903 CEST804972472.21.81.240192.168.2.4
                    Apr 17, 2024 01:51:21.624548912 CEST4972480192.168.2.472.21.81.240
                    Apr 17, 2024 01:51:21.625022888 CEST804972372.21.81.240192.168.2.4
                    Apr 17, 2024 01:51:21.625195026 CEST4972380192.168.2.472.21.81.240
                    Apr 17, 2024 01:51:23.736556053 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:23.736720085 CEST4434975264.233.176.147192.168.2.4
                    Apr 17, 2024 01:51:23.737215996 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:25.056369066 CEST49752443192.168.2.464.233.176.147
                    Apr 17, 2024 01:51:25.056438923 CEST4434975264.233.176.147192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 17, 2024 01:50:08.882204056 CEST53562661.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:08.917696953 CEST53526821.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:09.503505945 CEST53550741.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:10.122853041 CEST6416953192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:10.122973919 CEST5349553192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:10.228790998 CEST53641691.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:10.228842020 CEST53534951.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:10.699445963 CEST6047053192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:10.699614048 CEST5747753192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:10.807686090 CEST53574771.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:10.808645964 CEST53604701.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:13.443490982 CEST5535953192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:13.443679094 CEST6333953192.168.2.41.1.1.1
                    Apr 17, 2024 01:50:13.548398018 CEST53633391.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:13.548460007 CEST53553591.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:26.828438044 CEST53590871.1.1.1192.168.2.4
                    Apr 17, 2024 01:50:33.104592085 CEST138138192.168.2.4192.168.2.255
                    Apr 17, 2024 01:50:45.846559048 CEST53577971.1.1.1192.168.2.4
                    Apr 17, 2024 01:51:08.775903940 CEST53582621.1.1.1192.168.2.4
                    Apr 17, 2024 01:51:08.862860918 CEST53599241.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 17, 2024 01:50:10.122853041 CEST192.168.2.41.1.1.10x8490Standard query (0)email.notifications.joinhandshake.comA (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.122973919 CEST192.168.2.41.1.1.10x5452Standard query (0)email.notifications.joinhandshake.com65IN (0x0001)false
                    Apr 17, 2024 01:50:10.699445963 CEST192.168.2.41.1.1.10x7b8dStandard query (0)content-calpoly-edu.s3.amazonaws.comA (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.699614048 CEST192.168.2.41.1.1.10x72c8Standard query (0)content-calpoly-edu.s3.amazonaws.com65IN (0x0001)false
                    Apr 17, 2024 01:50:13.443490982 CEST192.168.2.41.1.1.10x8bf1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.443679094 CEST192.168.2.41.1.1.10xc593Standard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 17, 2024 01:50:10.228790998 CEST1.1.1.1192.168.2.40x8490No error (0)email.notifications.joinhandshake.commailgun.orgCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:10.228790998 CEST1.1.1.1192.168.2.40x8490No error (0)mailgun.org34.110.180.34A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.228842020 CEST1.1.1.1192.168.2.40x5452No error (0)email.notifications.joinhandshake.commailgun.orgCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:10.807686090 CEST1.1.1.1192.168.2.40x72c8No error (0)content-calpoly-edu.s3.amazonaws.coms3-us-west-1-w.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)content-calpoly-edu.s3.amazonaws.coms3-us-west-1-w.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.220.161A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.120.114A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.113.42A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.113.121A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.117.169A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.112.210A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.193.65A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:10.808645964 CEST1.1.1.1192.168.2.40x7b8dNo error (0)s3-us-west-1-w.amazonaws.com52.219.220.177A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548398018 CEST1.1.1.1192.168.2.40xc593No error (0)www.google.com65IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.147A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.106A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.105A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.104A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.103A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:13.548460007 CEST1.1.1.1192.168.2.40x8bf1No error (0)www.google.com64.233.176.99A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:25.554395914 CEST1.1.1.1192.168.2.40x66e2No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:25.554395914 CEST1.1.1.1192.168.2.40x66e2No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:25.923814058 CEST1.1.1.1192.168.2.40xa1e1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:25.923814058 CEST1.1.1.1192.168.2.40xa1e1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:50:39.736953020 CEST1.1.1.1192.168.2.40xc5d9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:50:39.736953020 CEST1.1.1.1192.168.2.40xc5d9No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:51:00.939133883 CEST1.1.1.1192.168.2.40x6440No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:51:00.939133883 CEST1.1.1.1192.168.2.40x6440No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 17, 2024 01:51:21.501446962 CEST1.1.1.1192.168.2.40x410cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 17, 2024 01:51:21.501446962 CEST1.1.1.1192.168.2.40x410cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • email.notifications.joinhandshake.com
                    • content-calpoly-edu.s3.amazonaws.com
                    • https:
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44973534.110.180.344435776C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-16 23:50:10 UTC1142OUTGET /c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX- HTTP/1.1
                    Host: email.notifications.joinhandshake.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-16 23:50:10 UTC535INHTTP/1.1 302 Found
                    Access-Control-Allow-Credentials: true
                    Access-Control-Allow-Origin: *
                    Cache-Control: no-store
                    Content-Length: 858
                    Content-Type: text/html
                    Date: Tue, 16 Apr 2024 23:50:10 GMT
                    Location: https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved
                    X-Robots-Tag: noindex
                    X-Xss-Protection: 1; mode=block
                    Connection: close
                    2024-04-16 23:50:10 UTC651INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 22 3e 0a 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 74 69 74 6c 65 3e 52 65 64 69 72 65 63 74 69 6e 67 2e 2e 2e 3c 2f 74 69 74 6c 65 3e 0a 3c 68 31 3e 52 65 64 69 72 65 63 74 69 6e 67 2e 2e 2e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 73 68 6f 75 6c 64 20 62 65 20 72 65
                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta name="robots" content="noindex"><meta charset="utf-8"></head><body><title>Redirecting...</title><h1>Redirecting...</h1><p>You should be re
                    2024-04-16 23:50:10 UTC207INData Raw: 53 70 72 69 6e 67 25 32 30 43 61 72 65 65 72 25 32 30 46 61 69 72 25 32 30 45 6d 70 6c 6f 79 65 72 25 32 30 43 68 65 63 6b 25 32 30 4c 69 73 74 25 32 30 61 6e 64 25 32 30 49 6e 66 6f 72 6d 61 74 69 6f 6e 25 32 30 56 32 2e 70 64 66 3f 75 74 6d 5f 73 6f 75 72 63 65 3d 6e 6f 74 69 66 69 65 72 26 61 6d 70 3b 75 74 6d 5f 6d 65 64 69 75 6d 3d 65 6d 61 69 6c 26 61 6d 70 3b 75 74 6d 5f 63 61 6d 70 61 69 67 6e 3d 73 65 6e 64 5f 72 65 67 69 73 74 72 61 74 69 6f 6e 5f 61 70 70 72 6f 76 65 64 3c 2f 61 3e 2e 20 20 49 66 20 6e 6f 74 20 63 6c 69 63 6b 20 74 68 65 20 6c 69 6e 6b 2e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
                    Data Ascii: Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&amp;utm_medium=email&amp;utm_campaign=send_registration_approved</a>. If not click the link.</body></html>


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44973752.219.220.1614435776C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-16 23:50:11 UTC880OUTGET /careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved HTTP/1.1
                    Host: content-calpoly-edu.s3.amazonaws.com
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-16 23:50:11 UTC474INHTTP/1.1 200 OK
                    x-amz-id-2: ZduT43//+gOdALiPkkE/kktyb9TmlkOKfC3mowfm1OWZbCkpL578RmkvjodUhRjpJYlbn2da4Bg=
                    x-amz-request-id: 7V23069Y90YTBGCJ
                    Date: Tue, 16 Apr 2024 23:50:12 GMT
                    Last-Modified: Mon, 25 Mar 2024 20:59:43 GMT
                    ETag: "b80cf06a3490c75aafc73a043f8fe12e"
                    x-amz-server-side-encryption: AES256
                    x-amz-version-id: uXsXhrmMrf_kTlXIxhhpmWx66tBiSo_T
                    Accept-Ranges: bytes
                    Content-Type: application/pdf
                    Server: AmazonS3
                    Content-Length: 412528
                    Connection: close
                    2024-04-16 23:50:11 UTC15818INData Raw: 25 50 44 46 2d 31 2e 36 0d 25 e2 e3 cf d3 0d 0a 34 39 34 20 30 20 6f 62 6a 0d 3c 3c 2f 4c 69 6e 65 61 72 69 7a 65 64 20 31 2f 4c 20 34 31 32 35 32 38 2f 4f 20 34 39 36 2f 45 20 32 33 37 39 36 37 2f 4e 20 37 2f 54 20 34 31 32 30 33 34 2f 48 20 5b 20 35 33 34 20 33 37 32 5d 3e 3e 0d 65 6e 64 6f 62 6a 0d 20 20 20 20 20 20 20 20 20 20 20 20 20 0d 0a 35 32 34 20 30 20 6f 62 6a 0d 3c 3c 2f 44 65 63 6f 64 65 50 61 72 6d 73 3c 3c 2f 43 6f 6c 75 6d 6e 73 20 35 2f 50 72 65 64 69 63 74 6f 72 20 31 32 3e 3e 2f 46 69 6c 74 65 72 2f 46 6c 61 74 65 44 65 63 6f 64 65 2f 49 44 5b 3c 31 37 35 34 30 44 45 44 44 35 34 39 39 39 34 42 38 34 32 32 38 41 42 37 39 42 30 37 32 37 45 30 3e 3c 33 33 45 30 37 31 34 46 45 32 42 39 33 31 34 34 39 42 31 36 41 32 36 33 37 41 37 35 42 41
                    Data Ascii: %PDF-1.6%494 0 obj<</Linearized 1/L 412528/O 496/E 237967/N 7/T 412034/H [ 534 372]>>endobj 524 0 obj<</DecodeParms<</Columns 5/Predictor 12>>/Filter/FlateDecode/ID[<17540DEDD549994B84228AB79B0727E0><33E0714FE2B931449B16A2637A75BA
                    2024-04-16 23:50:11 UTC16384INData Raw: 06 47 dc 0b 7d 2e ad a6 91 30 a3 44 d7 41 20 fe c4 31 32 16 c0 c7 ce fe d2 71 1d d2 3e b1 a7 56 6a 57 84 77 28 8e 91 8e 0c ed 81 76 45 5d af 56 2a b7 c4 c9 f8 dd f8 97 b1 fa 58 4d 2c a0 ec c0 28 6a ed c2 11 44 f1 11 3e 41 f2 39 83 f3 16 5f 83 93 38 8b 8b e8 fd bc 8e 1d 38 84 df e0 73 dc ef c1 76 e3 27 38 0a f3 29 bd 2d 16 7a 10 1f e0 38 4e a1 03 17 88 35 63 2b d1 9f e2 58 2f bd d7 b0 11 ef e0 5d b4 e1 aa 34 22 81 5d 90 33 24 3b 82 2e b8 e4 2b d2 4a 69 33 86 21 0f 05 a8 c0 4a 34 62 03 e3 ea 94 a6 13 9b 4c 6c 16 d1 15 a8 c7 36 a2 51 74 e2 7f 9f c9 28 43 25 6a b1 0c 11 6a 9c b3 b0 e7 88 96 a2 86 a8 c0 ec 67 39 1a b0 09 fb 71 18 a7 19 57 03 23 db 8a bd 7d d8 7b 5d f6 c8 1e ac c2 1d 9e fc 58 da 29 7f c4 8c 0e e3 2d 47 06 fa 01 ac fc 28 d1 01 ab b6 88 7f 09 c4
                    Data Ascii: G}.0DA 12q>VjWw(vE]V*XM,(jD>A9_88sv'8)-z8N5c+X/]4"]3$;.+Ji3!J4bLl6Qt(C%jjg9qW#}{]X)-G(
                    2024-04-16 23:50:11 UTC1024INData Raw: 17 ca fb 9d 07 3f da ea b7 4f 2e 94 f7 39 87 7f e3 72 a1 7c dc ff e1 47 5b f3 dc 37 17 ca fb 9e c3 8f 09 b9 50 3e 21 d7 0f e2 13 f7 d8 c6 7d dc 4d b7 60 df 71 f9 fe 23 ec 78 2c bb af f1 0f fc e7 7e 11 cf 74 cf ef b8 7a bf 80 5a 58 05 27 a1 c4 41 cc 8b a7 53 a7 06 fb 31 6c 84 49 4d 34 1e c0 5e 28 e6 97 8c 13 af 84 81 30 d9 8e a5 6d 1b 77 da b1 0d 6e cc c6 97 6c fb b3 cf 63 5f cd 79 fe 2a 1c b1 e3 99 b1 35 f6 ee c0 f6 81 d5 ee fb 96 ba 71 b7 5a df 1b 57 36 d5 6f bc d0 7e a3 69 b7 b5 89 d8 83 1b 69 df 0b 5b d1 44 e3 af 2d f1 1e ec 0b 70 08 f6 3b bf f4 7f 4f 37 1f fa cd 2f 6b 5f 4d 71 41 4e f9 ab 89 19 b7 89 90 ab bb 47 75 d6 fa f7 c9 78 13 73 df 68 96 ab be 6f e2 e1 bf 64 93 89 77 31 b1 ef 2a 19 1e 76 44 87 3c 23 25 aa 1b 34 86 07 77 98 fa cb 83 2a 72 93 a0
                    Data Ascii: ?O.9r|G[7P>!}M`q#x,~tzZX'AS1lIM4^(0mwnlc_y*5qZW6o~ii[D-p;O7/k_MqANGuxshodw1*vD<#%4w*r
                    2024-04-16 23:50:11 UTC16384INData Raw: 95 10 65 17 f5 b0 e7 80 3b d2 51 8b 4c 6d 6d 7e a2 3b ec fe 8b fa db 79 0a 4e cb ed 4e 7b 1d e6 3b 3a 6a 7c 57 5c ec eb 9b 5f 2e eb 4c 2c 98 2c bd 34 b6 90 77 f5 9c 5f e2 ff 4e 66 36 d7 7c 71 05 fb a6 48 cf 06 79 32 a0 7e 97 e0 1e 29 4d ff 31 7e 2e 58 48 4c 38 1e bf 1a 3c 80 16 00 c6 5a e2 38 e0 58 6b b5 5f fc 22 f6 4a 33 cf 57 c8 2b d8 cd d9 70 b7 ed a9 68 1d 9b 27 e3 0d 4e 6f ab 8e 5d 60 69 6c b0 e5 4d 7e 25 b1 d7 fb 9c ef 38 2d 45 aa 1b fc 6b a5 c8 e8 97 d9 52 03 45 de 31 de a3 17 f8 86 a5 de ed 32 4a 73 86 77 39 da 0a fd a1 7a c1 9c 05 91 6e fe fb 58 4b 47 e6 a5 dc db 94 75 be 07 c9 12 bf 92 79 02 d5 44 66 9d f6 91 03 b4 fe 3e d3 be d8 c5 c5 01 3a 96 f7 3d e2 f8 bb d2 2b 7d 8c 7a bc a3 dd 52 ed 23 d8 26 0b 55 17 79 dc 28 82 89 ec 8b 49 d4 9d 14 bf e5
                    Data Ascii: e;QLmm~;yNN{;:j|W\_.L,,4w_Nf6|qHy2~)M1~.XHL8<Z8Xk_"J3W+ph'No]`ilM~%8-EkRE12Jsw9znXKGuyDf>:=+}zR#&Uy(I
                    2024-04-16 23:50:11 UTC1024INData Raw: 1d 8d a4 fd 02 55 db c5 d8 82 e9 70 38 1d b4 d1 b5 37 28 5e 4e 81 3e c0 e7 12 c7 92 8f a6 5b 04 2c 31 38 2c 06 db 7a a3 27 7d 31 cf 9c e3 0f dc fe 4c b4 72 b4 8e 64 53 ff ed 3f dd d5 7f 3b 9b 33 2b f9 f6 3b 55 1a b7 2f 88 98 4d 30 ab 71 27 31 65 9d 0d 2d 42 53 da 29 9c 8e 99 b9 a4 d9 ec 28 53 5d 25 39 99 81 6e 1a c9 bd 23 6d 04 07 9b 59 a5 06 db 5a 93 61 c1 42 24 81 67 cd 65 fc f2 19 b8 f3 c8 7d 91 fc 27 f1 e5 16 dc c4 79 c5 f1 6f 6f 12 da 5d c9 ab db ae ae 16 ba df ec d5 5d f2 fa a6 35 16 be 61 19 63 03 26 05 83 31 94 90 40 26 50 08 ce 05 12 ea a6 4c a7 81 86 0c 25 84 a4 49 26 a4 a5 69 3b b4 89 71 89 52 28 d3 30 4c db 87 66 fa c2 a4 4c a6 99 84 a6 2f 50 fc d4 4e 33 03 46 ee b7 2b ad ac 40 d3 69 92 ce 74 34 23 ad a4 dd 9d 3d e7 fc cf ff fc 0e 3c ae 49 45
                    Data Ascii: Up87(^N>[,18,z'}1LrdS?;3+;U/M0q'1e-BS)(S]%9n#mYZaB$ge}'yoo]]5ac&1@&PL%I&i;qR(0LfL/PN3F+@it4#=<IE
                    2024-04-16 23:50:11 UTC16384INData Raw: 92 b4 bd 84 fe 60 06 d0 bc 34 e1 72 80 44 9a cf e9 73 f0 c5 b6 2b 19 69 2f 21 cd 22 dd 65 27 c2 a3 ac 2c 30 b6 84 ac ab f3 14 c9 7f a3 fa ca 3a c6 cc 49 4d 2a ef 66 92 2b 5d 00 fc ff e6 ae 8b ae 85 2b b2 95 d2 9a 49 f3 aa ea 77 95 f9 b3 dc ac c2 0e 0f 4e ff 7c 4b f7 9e 75 6d 36 0a 87 eb 98 2e 35 fc 70 7f 7c 30 e3 88 17 27 b7 4f 16 e3 cb 1f 79 f5 3e 7e c3 70 a7 49 4d a0 98 5a 4b 51 f1 9e 0d b9 a8 18 35 c7 56 6e dd be 75 28 8e 3c bd ed c5 fb d3 ac cb 63 4b f0 ae 88 8d 72 87 dc 5c a4 33 d0 94 4f 44 e3 1d 6b f6 ae 1a 3f 32 ce eb 2c 8d 26 1d e7 b5 39 43 36 da e1 b6 9b fd 69 67 b4 f2 ff 1e 98 75 1a 6e 76 37 a0 aa 3d 60 b4 ea 7e 40 05 37 bb b3 16 bd ca a0 a4 c1 20 2f 56 ce 45 c7 4a 22 b1 cb 77 de 93 44 fa 9f 4e 5a dc ba 16 a9 55 69 69 99 bb 6e c8 8b e8 05 89 ba
                    Data Ascii: `4rDs+i/!"e',0:IM*f+]+IwN|Kum6.5p|0'Oy>~pIMZKQ5Vnu(<cKr\3ODk?2,&9C6igunv7=`~@7 /VEJ"wDNZUiin
                    2024-04-16 23:50:11 UTC1024INData Raw: d1 5b a9 39 6e 17 e6 ec df d3 6b 5a 19 fd 92 fb 99 85 dc fd 90 07 0b 20 08 0d 30 9d ed 52 46 d2 73 ca 76 da a0 6e c6 fa 69 37 35 28 53 69 87 a4 26 77 23 93 5a 25 25 9d 9e 50 70 cd 4c f7 d3 5a 7c af 3d 92 52 27 5a 42 30 57 2c 83 4f 95 3a bc af cc 36 1a a6 ec c1 f7 ae c3 fa a3 0e f7 c8 6a 0b 70 5c c9 f1 67 1c 77 9b 7d c4 e3 37 85 ef e0 32 70 fd f2 a8 5c 2d a4 72 cd 85 e7 6d 0d 95 61 ed 32 57 6d a5 71 ea 55 b6 9e 32 6e ca bb 8e bc 8b c8 7b 05 cf 91 2d 0f 73 c9 5c b5 14 d7 6f 0d 9d 81 23 50 0e 83 60 21 9b 06 49 6c 36 f8 61 22 64 f3 67 c5 90 01 25 30 05 f2 21 8d 73 65 5e 0e 7f 3e 51 09 d2 59 38 06 cb c1 0f 01 58 0c 85 30 94 3d 04 e3 21 17 4a a1 88 f3 7e c8 9f cd e4 b6 b1 30 8f f3 f2 61 92 2c 6b 47 e5 b3 67 fd c9 b2 55 97 ef 32 a3 1d ce c3 61 2e 63 4f 65 74 02
                    Data Ascii: [9nkZ 0RFsvni75(Si&w#Z%%PpLZ|=R'ZB0W,O:6jp\gw}72p\-rma2WmqU2n{-s\o#P`!Il6a"dg%0!se^>QY8X0=!J~0a,kGgU2a.cOet
                    2024-04-16 23:50:11 UTC16384INData Raw: ae 92 68 fc 83 eb 35 2c 05 1a a0 ce 21 3f 85 cb 29 dd b0 e7 a5 44 94 ed 39 21 8d 50 05 59 5c 6f 62 15 50 0f b5 0e f9 15 5c ae b0 09 da ca f6 3c 67 e1 f3 40 23 54 41 16 d7 9b 98 cc ab 87 5a 87 fc 50 1f 15 36 41 5b d9 9e e7 ac 3f 72 6e 5f 75 2f 8f fb df 79 e0 ff d0 9a db cc 0f ff 4e 25 90 ab f4 c7 ef c2 aa d7 b0 14 68 70 b8 06 25 fc 59 0b 47 27 f6 bc 94 88 b2 3d 27 a4 11 aa 20 8b eb 4d 4c 3e 37 f5 50 eb 90 1f 7a a6 2a 6c 82 b6 b2 3d cf 59 f8 75 69 84 2a c8 e2 7a 13 93 79 f5 50 eb 90 1f ea a3 c2 26 68 2b db f3 1c 39 cc 75 7d 33 40 4c 8b a9 9b e7 dc be 89 f1 7e e1 a6 b9 3f 5a 9b 9c c5 fa fa b9 7f 87 77 63 2f f4 76 bf e3 3e 1d 4e 5b 12 0e eb 99 f7 e1 19 ac 99 66 41 42 c4 fb a6 9e 63 c0 d6 16 b0 d5 eb 6d f5 da 1b e5 28 d6 9e 3d 0a ff 6d d7 73 0c d8 da 02 b6 7a
                    Data Ascii: h5,!?)D9!PY\obP\<g@#TAZP6A[?rn_u/yN%hp%YG'=' ML>7Pz*l=Yui*zyP&h+9u}3@L~?Zwc/v>N[fABcm(=msz
                    2024-04-16 23:50:11 UTC1024INData Raw: 8d f4 ae 8e 07 27 dc d3 43 e3 18 ef 08 2b de 90 83 5f 99 83 c8 83 14 e7 1d 11 c5 13 76 f0 86 61 8d f4 10 79 e1 b0 80 db 22 6f d8 ba f2 7b 3d 36 fe 4d 8f 56 ee 1a 38 3d a6 68 93 7d 80 b6 93 39 84 68 2f 14 dc a3 ee d7 dd 2c 43 01 67 28 e0 0c 05 9c a1 80 33 14 70 e6 26 f4 7e cb da d2 02 e0 66 b1 95 35 70 00 94 7a c3 9f d3 6e 42 c6 eb 12 d5 53 22 fb f4 44 cc ce b0 db d3 f8 f9 f5 4f 86 af 6c 5a fb 27 f9 08 be 32 c9 7c b3 aa 71 99 ff e3 f3 54 f8 3c 89 0c ab 2d d1 b2 f9 16 c9 32 32 8c aa cc 35 13 9d f4 d0 94 6a 9f eb 9b 8b 96 65 f3 22 c9 ce 4d cb 26 45 1b eb 26 7d ac d7 6b 87 d3 dd 80 66 1b ea b9 7c e4 1f 3c 51 f6 e7 33 11 a1 c9 64 60 61 7a f3 9e 68 26 18 e9 0a d9 aa 49 ca 66 f2 c0 f0 85 fd dd 66 ab 24 8a 92 c7 ee 02 2b 60 b5 5b a5 cc 78 89 7d 05 33 c6 3a 63 e8
                    Data Ascii: 'C+_vay"o{=6MV8=h}9h/,Cg(3p&~f5pznBS"DOlZ'2|qT<-225je"M&E&}kf|<Q3d`azh&Iff$+`[x}3:c
                    2024-04-16 23:50:11 UTC16384INData Raw: fd 8d cb 66 39 ec c1 3e d7 e6 25 ce b6 e1 a3 8f 0f a5 e6 fb 27 2b ed af fe 78 e4 f0 03 31 f6 f2 a1 9f 1c 1f 58 cd d4 0a 10 28 d3 e4 2e 3c 72 6e 72 f4 58 4f cb ca 7f 93 3b a7 aa b8 18 05 c0 a5 97 19 64 de d2 98 12 b0 65 a4 3c 0f b9 e5 31 d7 bc 96 6b 1e 73 cf 23 5b f2 c0 96 85 54 11 fe 9b 2a 48 08 18 44 12 05 50 a2 00 4a 14 40 89 02 28 01 80 b3 fe 8c 0d ec c4 8d 93 45 52 2c ba b7 40 de f3 e1 71 37 6d 7b 9a 0b 59 ee d3 a9 93 d5 bb 1f 58 12 00 6c 36 53 c4 ad f3 d3 b0 31 8c 3b 6f 4c d3 ad 58 96 1a 68 7d 0d cd 2e c1 66 d8 cf a0 e7 72 07 58 54 e3 4d 50 99 b2 cb 45 7a e2 89 78 5c f7 69 02 e7 88 05 bc 61 87 60 3c eb ec d8 ba a7 ff b4 8e 2b f8 36 b9 bb e4 dd 7d 7a 24 11 dd f6 48 5f a8 a7 23 e9 f8 5a 0b bf ba 32 38 e6 29 e4 9e fb f9 e0 d4 b6 20 34 3e 98 82 66 68 39
                    Data Ascii: f9>%'+x1X(.<rnrXO;de<1ks#[T*HDPJ@(ER,@q7m{YXl6S1;oLXh}.frXTMPEzx\ia`<+6}z$H_#Z28) 4>fh9


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44974052.219.220.1614435776C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-16 23:50:12 UTC829OUTGET /favicon.ico HTTP/1.1
                    Host: content-calpoly-edu.s3.amazonaws.com
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-16 23:50:12 UTC285INHTTP/1.1 403 Forbidden
                    x-amz-request-id: XJNNKHPYFE50K4DG
                    x-amz-id-2: U2rAKxSCPjqS6N87DLDN153EYKeyfgzWZ6p1Aa6X52HwBPM++/0jxfeR/WZYN3JioxpjA2QMmZY=
                    Content-Type: application/xml
                    Transfer-Encoding: chunked
                    Date: Tue, 16 Apr 2024 23:50:11 GMT
                    Server: AmazonS3
                    Connection: close
                    2024-04-16 23:50:12 UTC254INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 58 4a 4e 4e 4b 48 50 59 46 45 35 30 4b 34 44 47 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 55 32 72 41 4b 78 53 43 50 6a 71 53 36 4e 38 37 44 4c 44 4e 31 35 33 45 59 4b 65 79 66 67 7a 57 5a 36 70 31 41 61 36 58 35 32 48 77 42 50 4d 2b 2b 2f 30 6a 78 66 65 52 2f 57 5a 59 4e 33 4a 69 6f 78 70 6a 41 32 51 4d 6d 5a 59 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a 30 0d 0a 0d 0a
                    Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>XJNNKHPYFE50K4DG</RequestId><HostId>U2rAKxSCPjqS6N87DLDN153EYKeyfgzWZ6p1Aa6X52HwBPM++/0jxfeR/WZYN3JioxpjA2QMmZY=</HostId></Error>0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449741104.123.200.136443
                    TimestampBytes transferredDirectionData
                    2024-04-16 23:50:13 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-16 23:50:14 UTC468INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/073D)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus2-z1
                    Cache-Control: public, max-age=112415
                    Date: Tue, 16 Apr 2024 23:50:14 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.449743104.123.200.136443
                    TimestampBytes transferredDirectionData
                    2024-04-16 23:50:14 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-16 23:50:14 UTC531INHTTP/1.1 200 OK
                    Content-Type: application/octet-stream
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=112334
                    Date: Tue, 16 Apr 2024 23:50:14 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-04-16 23:50:14 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:01:50:05
                    Start date:17/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:01:50:07
                    Start date:17/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1984,i,9554475306055727456,10145289589561791208,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:01:50:08
                    Start date:17/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly