Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E

Overview

General Information

Sample URL:http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E
Analysis ID:1427176
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5216 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3664 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2024,i,16078203422542096364,6056119984045768340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5EHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Wed, 17 Apr 2024 05:45:05 GMTContent-Type: application/javascript; charset=UTF-8Content-Length: 1188Connection: keep-aliveX-Sucuri-ID: 14006X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffcache-control: max-age=315360000expires: Thu, 31 Dec 2037 23:55:55 GMTlast-modified: Tue, 09 Apr 2024 20:44:22 GMTaccept-ranges: bytescontent-encoding: gzipvary: Accept-Encoding,Accept-Encoding,User-Agentx-turbo-charged-by: LiteSpeedX-Sucuri-Cache: MISSData Raw: 1f 8b 08 00 00 00 00 00 00 03 bd 58 5d 6f db 36 14 7d cf af 60 b4 c0 15 33 49 69 5e 65 78 5d 91 6e 58 0b ac c0 9a 3e 0c 18 86 80 11 af 2d 26 32 99 91 b4 dd cc f1 7f df a5 28 eb c3 b6 6c 27 d9 f6 12 58 e2 bd e7 1e 9e fb 41 2a 17 e7 e7 27 e4 9c 7c cd 85 21 9f ae c9 58 14 40 16 cc 10 36 b3 2a 9e 80 04 cd 2c 70 32 17 8c 7c 05 6d 40 27 68 ee 3c ae 94 b4 5a dc a2 99 36 c4 e4 6a 56 70 c2 e6 4a 70 02 5c 58 21 27 c4 3a 4c 07 18 11 34 23 42 1a 0b cc 2f e3 1a 10 66 8c ca 84 83 77 78 52 49 32 15 52 8c 05 86 2b 69 b8 3f 09 f9 59 69 32 55 1a d0 7f ac f4 94 59 a1 64 44 b2 1c b2 7b a2 10 56 cd 34 01 39 11 12 40 bb a8 5c 65 c6 e1 21 5c ae 16 64 01 24 67 92 23 1c ee ce e3 67 25 06 e2 ed f4 5d ef ef 47 03 90 92 dc da 07 93 5e 5c c0 5c da 44 98 0b 0e f3 d8 59 c5 6d 28 34 bf 38 39 71 6a 40 02 73 90 d6 8c da 0f 4f 4f cb 55 d4 7e 91 cc 05 2c ba 36 fe 55 8f 65 32 45 ad f3 5f d5 2d 0a f2 93 c7 47 bb f1 4c 66 2e 7a 78 16 a9 db 3b ba 0c 66 06 88 41 ef cc 06 c3 39 d3 e4 0c 89 ce a6 68 3e 3a 0b d7 3f e9 10 6d 13 03 05 64 2e 71 a3 65 c6 0a 90 9c e9 f4 cd 1f 9c 59 16 df 99 51 50 32 88 3d 83 b8 8c 1d 4f b4 e0 c1 9f 6f a2 b5 f9 07 f6 d8 eb b1 b6 a9 5c 39 7b 8c 33 28 0a 7c 74 1b d8 40 b9 2e a9 00 bf 2a b0 1c d2 20 d9 83 74 73 53 43 c5 a6 72 0b a2 69 4b 96 63 29 79 9f 6a d1 11 6a 83 78 9d 1d 35 ac 9f 23 68 75 d1 6e 6e aa 47 c7 35 c6 be 58 74 29 7e 80 31 9b 15 f6 b3 b2 22 83 2d e4 1c 1b 04 34 62 80 31 6c 02 26 ae c0 53 a9 6c 78 c8 14 23 d2 60 e5 8a 21 c9 0a 65 e0 7d 51 54 d5 d2 94 4a 86 8c 19 d6 bb a6 cb e6 77 32 16 92 87 9d c2 48 5a 29 a2 09 b0 2c 0f c3 1a 05 ad e1 5b e4 09 d0 65 59 6a fe 01 0b ad 7a 1b 39 70 8c fd 91 8f aa b5 84 59 ab c3 80 69 c1 62 b7 a8 55 61 02 1a 9d 55 86 e8 1a 04 74 58 bb 0d 06 61 b3 b4 c1 34 f8 2e f8 be 36 a4 bb 1a 86 65 99 d2 1c b9 56 4a ac 1f c3 8a 4c 1d 96 d2 46 af 76 83 6d 1b ae 28 f5 da fa 71 52 57 c9 55 21 b2 fb 5d 0a 47 2e f9 dd 74 57 62 f1 ce cb ad ed 75 13 d1 5f 3c 34 e2 4d ff 3c 03 65 bb c0 69 82 c9 9e d8 fc 87 b7 c3 6d d2 83 c1 69 2b ce bb 0d f6 89 86 a9 9a 43 09 13 56 4d 97 a9 29 76 46 cc 2e 2f 1f e3 5c 70 0e 32 a0 e9 a6 1f e3 fc a0 93 17 5c 3d 80 ec 0c bf 46 ec cd 24 2d f7 16 db 60 b0 b7 54 5c 9c 3d 95 12 d5 d8 6b e6 bd 1d d3 19 Data Ascii: X]o6}`3Ii^ex]nX>-&2(l'XA*'|!X@6*,p2|m@'h<Z6jVpJp\X!':L4#B/fwxRI2R+i?Yi2UYdD{V49@\e!\d$g#g%]G^\\
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Wed, 17 Apr 2024 05:45:06 GMTContent-Type: image/x-iconContent-Length: 1022Connection: keep-aliveX-Sucuri-ID: 14006X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffcache-control: max-age=315360000expires: Thu, 31 Dec 2037 23:55:55 GMTlast-modified: Wed, 27 Dec 2006 04:39:45 GMTaccept-ranges: bytescontent-encoding: gzipvary: Accept-Encoding,Accept-Encoding,User-Agentx-turbo-charged-by: LiteSpeedX-Sucuri-Cache: MISSData Raw: 1f 8b 08 00 00 00 00 00 00 03 dd 93 6b 54 14 44 18 86 9f 4d 34 c3 54 bc b0 a2 a9 ab 81 4a c8 45 6e c2 ba 22 cb 02 8b 0a 04 28 08 2a 2d 0a a2 40 0a 0a 69 28 20 0a 2e 24 98 19 20 48 21 82 4b 28 2d 97 95 8b 08 68 88 22 6e 96 9c 53 49 1d ef 96 76 d0 20 b5 08 d4 22 69 a1 e3 3f ff f5 af 77 ce 77 66 9e f9 e6 9c 99 6f e6 1d 10 e8 9a 81 01 43 8a 18 0e 42 5d 6f aa 8b c1 a9 19 ba 10 30 72 28 27 15 f0 52 0d 0c 0c c0 b9 47 d4 3a 40 54 92 92 42 6d 07 fa be 0a 42 dc cc 31 4c 2f 62 85 e6 22 22 33 2b ae fd d0 41 d5 f1 52 56 07 54 e2 1f b8 06 6b ab 2d c8 da 1f 32 b5 fc 3c 8b 73 8a d9 dc 7e 8f 69 8a 4c 52 83 1d 39 9c a3 25 53 32 9a 8c 7c 15 0b 37 27 20 59 ea 4e fd 8d fb b8 cd 9b ce 48 5b 0f 6e 77 3d a2 ba ae 15 c7 9a 6f 11 9d ef 26 ae f1 2b 4c 82 37 61 93 9a c3 98 ec 46 e6 44 95 60 91 5d 8e fe 89 6b c4 84 79 e2 9b 9a 41 bc eb 74 14 d1 e5 b4 68 b5 f8 5f b8 83 f1 b6 34 c4 a1 61 84 96 d6 e1 97 df ca 8c aa db 1c 51 9f 41 ee 6a 4b d1 a2 11 6c 88 8b a5 a7 fb 01 e3 d6 27 72 fa d2 0d 96 07 79 e1 70 f6 0e e6 0e b6 28 9b 2f 33 de 33 1a 59 59 1b 65 57 6e a3 48 c9 25 d1 d7 8c aa 8b 97 b0 54 b7 22 2b d0 e0 10 14 c0 72 2f 31 8f 9f f6 23 cd cc 65 d9 86 10 64 89 e9 64 c9 85 dc bd fb 13 ae 21 d1 cc 4e 2f 60 ca 91 d3 58 6f 4f 21 72 95 0b 2a 6b f0 3f d6 c0 37 5d 3d 18 b8 07 32 bb f6 3b 8e 36 9c 21 49 3c 16 a3 93 df 53 d8 f2 25 7a 4d f7 c8 b6 d7 a3 e0 ca 8f 48 0e 14 e3 bd 2f 0f c3 22 2d 63 13 55 18 9a 98 e1 11 19 8e dd a6 58 1e f7 3d c6 ac ed 3e b2 96 bb 94 a8 4b d1 5c be 4e c3 d5 5b 58 c6 ec c1 68 f7 21 bc fc 7c b0 c9 50 63 ac 6a c6 62 67 06 12 8d 16 49 6e 19 0a a7 59 cc 77 95 12 52 d3 8a 5a 02 a2 1d fb 99 5c f1 35 a2 7d 45 24 38 0b 11 47 44 f1 a0 a7 97 ce 5f ba 38 28 35 20 50 6a ce a4 b5 f1 78 a4 64 62 5a 71 89 88 f6 4e 0a db af f3 e4 c9 53 7c 74 7e 70 f1 70 c1 39 54 81 32 c8 06 61 42 31 92 b4 1c f2 24 c3 a9 e9 b8 49 a9 ba 19 61 e9 05 ec ca 2f 32 ca d2 8d 5d 12 43 7e fb a3 8f 70 b9 05 f2 bd b9 cc 54 e6 33 aa fe 1a c2 c3 a7 18 e8 ff 93 a6 9b f7 98 e0 bb 91 80 25 f6 d8 87 47 20 cd 3b 4e 95 23 24 e9 de d6 7b 6f 36 bb 57 da b3 c6 c5 04 93 63 2d 38 2b b3 30 55 b7 e1 9e 9c c6 cf 9d bf 22 52 9d a5 6c 70 ad d3 44 fa fa 7a b1 db 91 8a 63 5a 36 95 ba 1a 93 17 8c 63 e0 79 3f d5 62 08 93 cf 25 62 6b 1c 4f 9e 3d c3 71 5d 18 7e 3b 95 54 eb bc fd 7b 6f af Data Ascii: kTDM4TJEn"(*-@i( .$ H!K(-h"nSIv "i?wwfoCB]o0r('RG:@TBmB1L/b""3+ARVTk-2<s~
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Sucuri/CloudproxyDate: Wed, 17 Apr 2024 05:45:08 GMTContent-Type: image/x-iconContent-Length: 1022Connection: keep-aliveX-Sucuri-ID: 14006X-XSS-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffcache-control: max-age=315360000expires: Thu, 31 Dec 2037 23:55:55 GMTlast-modified: Wed, 27 Dec 2006 04:39:45 GMTcontent-encoding: gzipvary: Accept-Encoding,Accept-Encoding,User-Agentx-turbo-charged-by: LiteSpeedX-Sucuri-Cache: MISSAccept-Ranges: bytesData Raw: 1f 8b 08 00 00 00 00 00 00 03 dd 93 6b 54 14 44 18 86 9f 4d 34 c3 54 bc b0 a2 a9 ab 81 4a c8 45 6e c2 ba 22 cb 02 8b 0a 04 28 08 2a 2d 0a a2 40 0a 0a 69 28 20 0a 2e 24 98 19 20 48 21 82 4b 28 2d 97 95 8b 08 68 88 22 6e 96 9c 53 49 1d ef 96 76 d0 20 b5 08 d4 22 69 a1 e3 3f ff f5 af 77 ce 77 66 9e f9 e6 9c 99 6f e6 1d 10 e8 9a 81 01 43 8a 18 0e 42 5d 6f aa 8b c1 a9 19 ba 10 30 72 28 27 15 f0 52 0d 0c 0c c0 b9 47 d4 3a 40 54 92 92 42 6d 07 fa be 0a 42 dc cc 31 4c 2f 62 85 e6 22 22 33 2b ae fd d0 41 d5 f1 52 56 07 54 e2 1f b8 06 6b ab 2d c8 da 1f 32 b5 fc 3c 8b 73 8a d9 dc 7e 8f 69 8a 4c 52 83 1d 39 9c a3 25 53 32 9a 8c 7c 15 0b 37 27 20 59 ea 4e fd 8d fb b8 cd 9b ce 48 5b 0f 6e 77 3d a2 ba ae 15 c7 9a 6f 11 9d ef 26 ae f1 2b 4c 82 37 61 93 9a c3 98 ec 46 e6 44 95 60 91 5d 8e fe 89 6b c4 84 79 e2 9b 9a 41 bc eb 74 14 d1 e5 b4 68 b5 f8 5f b8 83 f1 b6 34 c4 a1 61 84 96 d6 e1 97 df ca 8c aa db 1c 51 9f 41 ee 6a 4b d1 a2 11 6c 88 8b a5 a7 fb 01 e3 d6 27 72 fa d2 0d 96 07 79 e1 70 f6 0e e6 0e b6 28 9b 2f 33 de 33 1a 59 59 1b 65 57 6e a3 48 c9 25 d1 d7 8c aa 8b 97 b0 54 b7 22 2b d0 e0 10 14 c0 72 2f 31 8f 9f f6 23 cd cc 65 d9 86 10 64 89 e9 64 c9 85 dc bd fb 13 ae 21 d1 cc 4e 2f 60 ca 91 d3 58 6f 4f 21 72 95 0b 2a 6b f0 3f d6 c0 37 5d 3d 18 b8 07 32 bb f6 3b 8e 36 9c 21 49 3c 16 a3 93 df 53 d8 f2 25 7a 4d f7 c8 b6 d7 a3 e0 ca 8f 48 0e 14 e3 bd 2f 0f c3 22 2d 63 13 55 18 9a 98 e1 11 19 8e dd a6 58 1e f7 3d c6 ac ed 3e b2 96 bb 94 a8 4b d1 5c be 4e c3 d5 5b 58 c6 ec c1 68 f7 21 bc fc 7c b0 c9 50 63 ac 6a c6 62 67 06 12 8d 16 49 6e 19 0a a7 59 cc 77 95 12 52 d3 8a 5a 02 a2 1d fb 99 5c f1 35 a2 7d 45 24 38 0b 11 47 44 f1 a0 a7 97 ce 5f ba 38 28 35 20 50 6a ce a4 b5 f1 78 a4 64 62 5a 71 89 88 f6 4e 0a db af f3 e4 c9 53 7c 74 7e 70 f1 70 c1 39 54 81 32 c8 06 61 42 31 92 b4 1c f2 24 c3 a9 e9 b8 49 a9 ba 19 61 e9 05 ec ca 2f 32 ca d2 8d 5d 12 43 7e fb a3 8f 70 b9 05 f2 bd b9 cc 54 e6 33 aa fe 1a c2 c3 a7 18 e8 ff 93 a6 9b f7 98 e0 bb 91 80 25 f6 d8 87 47 20 cd 3b 4e 95 23 24 e9 de d6 7b 6f 36 bb 57 da b3 c6 c5 04 93 63 2d 38 2b b3 30 55 b7 e1 9e 9c c6 cf 9d bf 22 52 9d a5 6c 70 ad d3 44 fa fa 7a b1 db 91 8a 63 5a 36 95 ba 1a 93 17 8c 63 e0 79 3f d5 62 08 93 cf 25 62 6b 1c 4f 9e 3d c3 71 5d 18 7e 3b 95 54 eb bc fd 7b 6f af Data Ascii: kTDM4TJEn"(*-@i( .$ H!K(-h"nSIv "i?wwfoCB]o0r('RG:@TBmB1L/b""3+ARVTk-2<s~
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E HTTP/1.1Host: lionsclubs.org.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lionsclubs.org.auConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5EAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lionsclubs.org.auConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: lionsclubs.org.au
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@7/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2024,i,16078203422542096364,6056119984045768340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2024,i,16078203422542096364,6056119984045768340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    lionsclubs.org.au
    192.124.249.106
    truefalse
      unknown
      www.google.com
      74.125.138.105
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://lionsclubs.org.au/favicon.icofalse
            unknown
            http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5Efalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              74.125.138.105
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              192.124.249.106
              lionsclubs.org.auUnited States
              30148SUCURI-SECUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1427176
              Start date and time:2024-04-17 07:44:11 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 14s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/5@7/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.9.94, 74.125.138.101, 74.125.138.100, 74.125.138.102, 74.125.138.113, 74.125.138.139, 74.125.138.138, 64.233.176.84, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.211.108, 20.242.39.171, 74.125.138.94, 74.125.136.113, 74.125.136.102, 74.125.136.138, 74.125.136.100, 74.125.136.139, 74.125.136.101
              • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:gzip compressed data, from Unix, original size modulo 2^32 1406
              Category:downloaded
              Size (bytes):1022
              Entropy (8bit):7.822097556429708
              Encrypted:false
              SSDEEP:24:XUqnQDzAek4iHOw27zm2KSFo/fQ+fwolNJW:XZKzrk4KO1aNnwolNJW
              MD5:3C29128645992C372F9191045E1F1F69
              SHA1:D2FB79C4538AEEF3E2CB4027098D5221A287E4FC
              SHA-256:80E8FC7B04BA573E496D0F2DDE5DB9C13F1291D25F50A1B40BB481F7DF30D8BB
              SHA-512:FBAB44DCAD95DC7D0DF0F7A0F3CCAFA186AB1A0CB231CDF773F9C9CFB2AFFB59F47F14CFE223315B998DF810506C94EC7E9B862E46A7FC9B15E6BA185BCDBA88
              Malicious:false
              Reputation:low
              URL:http://lionsclubs.org.au/favicon.ico
              Preview:...........kT.D...M4.T......J.En.".....(.*-..@..i( ..$.. H!.K(-....h."n..SI..v. ..."i..?...w.wf...o.....C...B]o.......0r('..R.....G.:@T..Bm....B..1L/b..""3+...A..RV.T....k.-...2..<.s...~.i.LR..9..%S2..|..7' Y.N......H[.nw=.....o...&..+L.7a....F.D.`.]...k.y.A..t...h.._...4.a.........Q.A.jK..l........'r.....y.p.....(./3.3.YY.eWn.H.%......T."+.....r/1...#..e..d..d.....!..N/`..XoO!r..*k.?..7]=...2..;.6.!I<....S..%zM.....H.../.."-c.U........X..=..>.....K.\.N..[X...h.!..|..Pc.j.bg....In...Y.w..R.Z.....\.5.}E$8..GD..._.8(5 Pj...x.dbZq...N.....S|t~p.p.9T.2..aB1....$..I...a..../2..].C~...p....T.3...............%..G .;N.#$...{o6.W.....c-8+.0U....."R..lp..D..z...cZ6......c.y?.b...%bk.O.=.q].~;.T..{o...........k."..........s..%.T..7.ws..P......+8./..<^.wl..o....s.l..O.^.Q.|`.....6.......F.|V.td.TOs..A.....}.S.........i...l...8_..y....JLs.......)...../?.xx.....u...y..w..|W..u`...9..fX..|P......5.T.>t...KUg..Nj.Z.8=.`O.xy.....
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:gzip compressed data, from Unix, original size modulo 2^32 4614
              Category:downloaded
              Size (bytes):1188
              Entropy (8bit):7.8394003711408295
              Encrypted:false
              SSDEEP:24:X5Xyappc1y+136WDRru9Gd4uI5kbfMZVozrcrkQmY+uT:X5X+1y2Dru9mIpT0rgkHST
              MD5:F6CAB815843A8794392B401E915EC43E
              SHA1:E25FC68767D3325DB66B3D545730BEF3003BE33D
              SHA-256:50B6827349E5FC1F49D3747472F1B0BEE255D4F514EFFC1052167CCA655197A9
              SHA-512:B6460FFAEA88BADB37187675F660C49401B274A9FE9B31F6C200618D8C7BE163E0F8D2E42680378CB2C2C475063B8200E24F5082FC34F56374FFDA336970699A
              Malicious:false
              Reputation:low
              URL:http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E
              Preview:...........X]o.6.}.`...3Ii^ex].nX....>......-&2........(..l'...X.....A*...'.|.!...X.@...6.*....,p2..|.m@'h.<...Z..6..jVp..Jp.\X!'.:L...4#B.../...f...wxRI2.R...+i.?..Yi2U......Y.dD...{..V.4.9..@..\e..!\..d.$g.#....g%....]..G.......^\.\.D.....Y.m(4.89qj@.s....OO.U.~...,.6.U.e2E.._.-...G..Lf.zx...;..f..A....9.....h>:..?..m...d.q.e.........Y..QP2.=....O....o........\9{.3(.|t..@.....*... .tsSC.r..iK.c)y.j..j.x..5..#hu.nn.G.5.Xt)~.1.....".-....4b.1l.&..S.lx..#.`.!..e.}QT..J.......w2.....HZ)...,......[...eYj....z.9p.......Y..i.b..Ua...U....tX...a...4....6....e....VJ...L...F.v.m..(...qRW.U!..].G...tWb....u.._<4.M.<.e..i.......m..i+.......C..VM..)vF../..\p.2........\=....F..$-...`..T\.=....k....jX\..3.BH.z.C....jw..W...Z.vE.J.~.g.d.dR..T.j..F....'I...k-[.'`...h.3.b..G....v.o)M...}...tIw.....s;..(.U....y.e.;~.x.r.j<....,.)..<9..........2.=..M.zOK_.)..j"i+.........x...........8.hdJ.%.so..G.%X!.....`\?W..w,.......j.....u.._.`..M.W..(.T....#f...l..oi.#.
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:gzip compressed data, from Unix, original size modulo 2^32 1406
              Category:dropped
              Size (bytes):1022
              Entropy (8bit):7.822097556429708
              Encrypted:false
              SSDEEP:24:XUqnQDzAek4iHOw27zm2KSFo/fQ+fwolNJW:XZKzrk4KO1aNnwolNJW
              MD5:3C29128645992C372F9191045E1F1F69
              SHA1:D2FB79C4538AEEF3E2CB4027098D5221A287E4FC
              SHA-256:80E8FC7B04BA573E496D0F2DDE5DB9C13F1291D25F50A1B40BB481F7DF30D8BB
              SHA-512:FBAB44DCAD95DC7D0DF0F7A0F3CCAFA186AB1A0CB231CDF773F9C9CFB2AFFB59F47F14CFE223315B998DF810506C94EC7E9B862E46A7FC9B15E6BA185BCDBA88
              Malicious:false
              Reputation:low
              Preview:...........kT.D...M4.T......J.En.".....(.*-..@..i( ..$.. H!.K(-....h."n..SI..v. ..."i..?...w.wf...o.....C...B]o.......0r('..R.....G.:@T..Bm....B..1L/b..""3+...A..RV.T....k.-...2..<.s...~.i.LR..9..%S2..|..7' Y.N......H[.nw=.....o...&..+L.7a....F.D.`.]...k.y.A..t...h.._...4.a.........Q.A.jK..l........'r.....y.p.....(./3.3.YY.eWn.H.%......T."+.....r/1...#..e..d..d.....!..N/`..XoO!r..*k.?..7]=...2..;.6.!I<....S..%zM.....H.../.."-c.U........X..=..>.....K.\.N..[X...h.!..|..Pc.j.bg....In...Y.w..R.Z.....\.5.}E$8..GD..._.8(5 Pj...x.dbZq...N.....S|t~p.p.9T.2..aB1....$..I...a..../2..].C~...p....T.3...............%..G .;N.#$...{o6.W.....c-8+.0U....."R..lp..D..z...cZ6......c.y?.b...%bk.O.=.q].~;.T..{o...........k."..........s..%.T..7.ws..P......+8./..<^.wl..o....s.l..O.^.Q.|`.....6.......F.|V.td.TOs..A.....}.S.........i...l...8_..y....JLs.......)...../?.xx.....u...y..w..|W..u`...9..fX..|P......5.T.>t...KUg..Nj.Z.8=.`O.xy.....
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 07:44:56.610997915 CEST49675443192.168.2.4173.222.162.32
              Apr 17, 2024 07:45:05.377947092 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:05.378357887 CEST4973880192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:05.494236946 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:05.494488001 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:05.494599104 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:05.494718075 CEST8049738192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:05.494896889 CEST4973880192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:05.610671043 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.036513090 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.036576986 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.036755085 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:06.210756063 CEST49675443192.168.2.4173.222.162.32
              Apr 17, 2024 07:45:06.303270102 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:06.419975042 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.500834942 CEST8049738192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.501110077 CEST4973880192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:06.633960009 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.634020090 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:06.634289980 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:07.257522106 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.257565975 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.257620096 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.258744001 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.258761883 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.484123945 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.486876011 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.486891985 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.488559961 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.488617897 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.495260000 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.495492935 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.535577059 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.535588980 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:07.582535028 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:07.865305901 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:07.867525101 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:07.867608070 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:07.867690086 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:07.870028973 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:07.870059967 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:07.957863092 CEST4974280192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:07.982357025 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:07.982446909 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:07.982923985 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:08.074481964 CEST8049742192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:08.074642897 CEST4974280192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:08.099725008 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:08.101877928 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.102072001 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.105336905 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.105390072 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.105926037 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.138987064 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.180190086 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.295710087 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.295866966 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.296040058 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.296041012 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.296041012 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.337876081 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.337956905 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.338061094 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.338500977 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.338555098 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.560271025 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.560367107 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.562830925 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.562855959 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.563235998 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.564765930 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.598136902 CEST49741443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.598234892 CEST4434974123.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.608195066 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.771656036 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.772166014 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.772233009 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.790781021 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.790781021 CEST49743443192.168.2.423.55.253.34
              Apr 17, 2024 07:45:08.790843010 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.790879011 CEST4434974323.55.253.34192.168.2.4
              Apr 17, 2024 07:45:08.819257975 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:08.819322109 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:08.819365025 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:09.124756098 CEST8049742192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:09.124819994 CEST4974280192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:17.513995886 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:17.514144897 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:17.514208078 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:18.951153040 CEST49739443192.168.2.474.125.138.105
              Apr 17, 2024 07:45:18.951178074 CEST4434973974.125.138.105192.168.2.4
              Apr 17, 2024 07:45:26.175849915 CEST8049738192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:26.176044941 CEST4973880192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:26.948913097 CEST4973880192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:27.065761089 CEST8049738192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:29.194804907 CEST8049742192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:29.194874048 CEST4974280192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:30.941936970 CEST4974280192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:31.058429003 CEST8049742192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:51.641793966 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:51.758398056 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:45:53.829222918 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:45:53.946228981 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:46:07.172872066 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:07.172916889 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.173145056 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:07.173384905 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:07.173403978 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.389729977 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.390079021 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:07.390103102 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.390804052 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.391204119 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:07.391308069 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:07.437174082 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:11.170152903 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:46:11.170233011 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:46:12.993427992 CEST4973780192.168.2.4192.124.249.106
              Apr 17, 2024 07:46:13.110047102 CEST8049737192.124.249.106192.168.2.4
              Apr 17, 2024 07:46:13.182337999 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:46:13.182413101 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:46:13.563502073 CEST4972480192.168.2.472.21.81.240
              Apr 17, 2024 07:46:13.563571930 CEST4972380192.168.2.472.21.81.240
              Apr 17, 2024 07:46:13.667618990 CEST804972372.21.81.240192.168.2.4
              Apr 17, 2024 07:46:13.667680025 CEST804972472.21.81.240192.168.2.4
              Apr 17, 2024 07:46:13.667757988 CEST4972480192.168.2.472.21.81.240
              Apr 17, 2024 07:46:13.667804956 CEST4972380192.168.2.472.21.81.240
              Apr 17, 2024 07:46:14.940063000 CEST4974080192.168.2.4192.124.249.106
              Apr 17, 2024 07:46:15.056685925 CEST8049740192.124.249.106192.168.2.4
              Apr 17, 2024 07:46:17.410167933 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:17.410326958 CEST4434975174.125.138.105192.168.2.4
              Apr 17, 2024 07:46:17.410406113 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:18.941967964 CEST49751443192.168.2.474.125.138.105
              Apr 17, 2024 07:46:18.942029953 CEST4434975174.125.138.105192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 07:45:02.812233925 CEST53536221.1.1.1192.168.2.4
              Apr 17, 2024 07:45:02.894093990 CEST53517441.1.1.1192.168.2.4
              Apr 17, 2024 07:45:03.495524883 CEST53617731.1.1.1192.168.2.4
              Apr 17, 2024 07:45:04.746685028 CEST6536553192.168.2.41.1.1.1
              Apr 17, 2024 07:45:04.748238087 CEST5002353192.168.2.41.1.1.1
              Apr 17, 2024 07:45:05.321813107 CEST53653651.1.1.1192.168.2.4
              Apr 17, 2024 07:45:05.806497097 CEST53500231.1.1.1192.168.2.4
              Apr 17, 2024 07:45:06.644529104 CEST6172753192.168.2.41.1.1.1
              Apr 17, 2024 07:45:06.644649982 CEST6303453192.168.2.41.1.1.1
              Apr 17, 2024 07:45:06.752372980 CEST53630341.1.1.1192.168.2.4
              Apr 17, 2024 07:45:07.138731003 CEST4989953192.168.2.41.1.1.1
              Apr 17, 2024 07:45:07.139019012 CEST5365753192.168.2.41.1.1.1
              Apr 17, 2024 07:45:07.243740082 CEST53498991.1.1.1192.168.2.4
              Apr 17, 2024 07:45:07.243803978 CEST53536571.1.1.1192.168.2.4
              Apr 17, 2024 07:45:07.670625925 CEST6287053192.168.2.41.1.1.1
              Apr 17, 2024 07:45:07.792207003 CEST53617271.1.1.1192.168.2.4
              Apr 17, 2024 07:45:08.207508087 CEST53628701.1.1.1192.168.2.4
              Apr 17, 2024 07:45:20.630614996 CEST53561821.1.1.1192.168.2.4
              Apr 17, 2024 07:45:25.127728939 CEST138138192.168.2.4192.168.2.255
              Apr 17, 2024 07:45:41.857311010 CEST53638171.1.1.1192.168.2.4
              Apr 17, 2024 07:46:03.675551891 CEST53580171.1.1.1192.168.2.4
              Apr 17, 2024 07:46:05.560405016 CEST53501661.1.1.1192.168.2.4
              Apr 17, 2024 07:46:31.657341957 CEST53549881.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Apr 17, 2024 07:45:05.806619883 CEST192.168.2.41.1.1.1c233(Port unreachable)Destination Unreachable
              Apr 17, 2024 07:45:08.207618952 CEST192.168.2.41.1.1.1c1f7(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 17, 2024 07:45:04.746685028 CEST192.168.2.41.1.1.10x66b6Standard query (0)lionsclubs.org.auA (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:04.748238087 CEST192.168.2.41.1.1.10x691aStandard query (0)lionsclubs.org.au65IN (0x0001)false
              Apr 17, 2024 07:45:06.644529104 CEST192.168.2.41.1.1.10x3b77Standard query (0)lionsclubs.org.auA (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:06.644649982 CEST192.168.2.41.1.1.10x8d61Standard query (0)lionsclubs.org.au65IN (0x0001)false
              Apr 17, 2024 07:45:07.138731003 CEST192.168.2.41.1.1.10x6797Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.139019012 CEST192.168.2.41.1.1.10xdf04Standard query (0)www.google.com65IN (0x0001)false
              Apr 17, 2024 07:45:07.670625925 CEST192.168.2.41.1.1.10x8138Standard query (0)lionsclubs.org.auA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 17, 2024 07:45:05.321813107 CEST1.1.1.1192.168.2.40x66b6No error (0)lionsclubs.org.au192.124.249.106A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.105A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.106A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.99A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.104A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.103A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243740082 CEST1.1.1.1192.168.2.40x6797No error (0)www.google.com74.125.138.147A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:07.243803978 CEST1.1.1.1192.168.2.40xdf04No error (0)www.google.com65IN (0x0001)false
              Apr 17, 2024 07:45:07.792207003 CEST1.1.1.1192.168.2.40x3b77No error (0)lionsclubs.org.au192.124.249.106A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:08.207508087 CEST1.1.1.1192.168.2.40x8138No error (0)lionsclubs.org.au192.124.249.106A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:19.692755938 CEST1.1.1.1192.168.2.40x87c1No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:19.692755938 CEST1.1.1.1192.168.2.40x87c1No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:21.207356930 CEST1.1.1.1192.168.2.40x37d5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 07:45:21.207356930 CEST1.1.1.1192.168.2.40x37d5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:35.157124043 CEST1.1.1.1192.168.2.40xefabNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 07:45:35.157124043 CEST1.1.1.1192.168.2.40xefabNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 07:45:57.306588888 CEST1.1.1.1192.168.2.40xee65No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 07:45:57.306588888 CEST1.1.1.1192.168.2.40xee65No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 07:46:17.155265093 CEST1.1.1.1192.168.2.40x415aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 07:46:17.155265093 CEST1.1.1.1192.168.2.40x415aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • fs.microsoft.com
              • lionsclubs.org.au
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449737192.124.249.106803664C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 17, 2024 07:45:05.494599104 CEST536OUTGET /wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E HTTP/1.1
              Host: lionsclubs.org.au
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 17, 2024 07:45:06.036513090 CEST1289INHTTP/1.1 200 OK
              Server: Sucuri/Cloudproxy
              Date: Wed, 17 Apr 2024 05:45:05 GMT
              Content-Type: application/javascript; charset=UTF-8
              Content-Length: 1188
              Connection: keep-alive
              X-Sucuri-ID: 14006
              X-XSS-Protection: 1; mode=block
              X-Frame-Options: SAMEORIGIN
              X-Content-Type-Options: nosniff
              cache-control: max-age=315360000
              expires: Thu, 31 Dec 2037 23:55:55 GMT
              last-modified: Tue, 09 Apr 2024 20:44:22 GMT
              accept-ranges: bytes
              content-encoding: gzip
              vary: Accept-Encoding,Accept-Encoding,User-Agent
              x-turbo-charged-by: LiteSpeed
              X-Sucuri-Cache: MISS
              Data Raw: 1f 8b 08 00 00 00 00 00 00 03 bd 58 5d 6f db 36 14 7d cf af 60 b4 c0 15 33 49 69 5e 65 78 5d 91 6e 58 0b ac c0 9a 3e 0c 18 86 80 11 af 2d 26 32 99 91 b4 dd cc f1 7f df a5 28 eb c3 b6 6c 27 d9 f6 12 58 e2 bd e7 1e 9e fb 41 2a 17 e7 e7 27 e4 9c 7c cd 85 21 9f ae c9 58 14 40 16 cc 10 36 b3 2a 9e 80 04 cd 2c 70 32 17 8c 7c 05 6d 40 27 68 ee 3c ae 94 b4 5a dc a2 99 36 c4 e4 6a 56 70 c2 e6 4a 70 02 5c 58 21 27 c4 3a 4c 07 18 11 34 23 42 1a 0b cc 2f e3 1a 10 66 8c ca 84 83 77 78 52 49 32 15 52 8c 05 86 2b 69 b8 3f 09 f9 59 69 32 55 1a d0 7f ac f4 94 59 a1 64 44 b2 1c b2 7b a2 10 56 cd 34 01 39 11 12 40 bb a8 5c 65 c6 e1 21 5c ae 16 64 01 24 67 92 23 1c ee ce e3 67 25 06 e2 ed f4 5d ef ef 47 03 90 92 dc da 07 93 5e 5c c0 5c da 44 98 0b 0e f3 d8 59 c5 6d 28 34 bf 38 39 71 6a 40 02 73 90 d6 8c da 0f 4f 4f cb 55 d4 7e 91 cc 05 2c ba 36 fe 55 8f 65 32 45 ad f3 5f d5 2d 0a f2 93 c7 47 bb f1 4c 66 2e 7a 78 16 a9 db 3b ba 0c 66 06 88 41 ef cc 06 c3 39 d3 e4 0c 89 ce a6 68 3e 3a 0b d7 3f e9 10 6d 13 03 05 64 2e 71 a3 65 c6 0a 90 9c e9 f4 cd 1f 9c 59 16 df 99 51 50 32 88 3d 83 b8 8c 1d 4f b4 e0 c1 9f 6f a2 b5 f9 07 f6 d8 eb b1 b6 a9 5c 39 7b 8c 33 28 0a 7c 74 1b d8 40 b9 2e a9 00 bf 2a b0 1c d2 20 d9 83 74 73 53 43 c5 a6 72 0b a2 69 4b 96 63 29 79 9f 6a d1 11 6a 83 78 9d 1d 35 ac 9f 23 68 75 d1 6e 6e aa 47 c7 35 c6 be 58 74 29 7e 80 31 9b 15 f6 b3 b2 22 83 2d e4 1c 1b 04 34 62 80 31 6c 02 26 ae c0 53 a9 6c 78 c8 14 23 d2 60 e5 8a 21 c9 0a 65 e0 7d 51 54 d5 d2 94 4a 86 8c 19 d6 bb a6 cb e6 77 32 16 92 87 9d c2 48 5a 29 a2 09 b0 2c 0f c3 1a 05 ad e1 5b e4 09 d0 65 59 6a fe 01 0b ad 7a 1b 39 70 8c fd 91 8f aa b5 84 59 ab c3 80 69 c1 62 b7 a8 55 61 02 1a 9d 55 86 e8 1a 04 74 58 bb 0d 06 61 b3 b4 c1 34 f8 2e f8 be 36 a4 bb 1a 86 65 99 d2 1c b9 56 4a ac 1f c3 8a 4c 1d 96 d2 46 af 76 83 6d 1b ae 28 f5 da fa 71 52 57 c9 55 21 b2 fb 5d 0a 47 2e f9 dd 74 57 62 f1 ce cb ad ed 75 13 d1 5f 3c 34 e2 4d ff 3c 03 65 bb c0 69 82 c9 9e d8 fc 87 b7 c3 6d d2 83 c1 69 2b ce bb 0d f6 89 86 a9 9a 43 09 13 56 4d 97 a9 29 76 46 cc 2e 2f 1f e3 5c 70 0e 32 a0 e9 a6 1f e3 fc a0 93 17 5c 3d 80 ec 0c bf 46 ec cd 24 2d f7 16 db 60 b0 b7 54 5c 9c 3d 95 12 d5 d8 6b e6 bd 1d d3 19
              Data Ascii: X]o6}`3Ii^ex]nX>-&2(l'XA*'|!X@6*,p2|m@'h<Z6jVpJp\X!':L4#B/fwxRI2R+i?Yi2UYdD{V49@\e!\d$g#g%]G^\\DYm(489qj@sOOU~,6Ue2E_-GLf.zx;fA9h>:?md.qeYQP2=Oo\9{3(|t@.* tsSCriKc)yjjx5#hunnG5Xt)~1"-4b1l&Slx#`!e}QTJw2HZ),[eYjz9pYibUaUtXa4.6eVJLFvm(qRWU!]G.tWbu_<4M<eimi+CVM)vF./\p2\=F$-`T\=k
              Apr 17, 2024 07:45:06.036576986 CEST465INData Raw: 6a 58 5c f8 f7 33 9b 42 48 9b 7a ef 43 d9 9f a8 0e d6 6a 77 e9 fe 57 f2 1c ea a4 5a 9f 76 45 bc 4a a2 7e a0 67 ab 64 d5 64 52 f4 c8 54 ee b7 6a cd ba 89 46 e5 db c4 1d 27 49 d3 d2 cd 9c 6b 2d 5b a6 27 60 ff cf 91 d7 68 9d 33 f3 62 a1 df 85 47 8e
              Data Ascii: jX\3BHzCjwWZvEJ~gddRTjF'Ik-['`h3bGvo)M}tIws;(Uye;~xrj<,)<92=MzOK_)j"i+x8hdJ%soG%X!`\?Ww,ju.
              Apr 17, 2024 07:45:06.303270102 CEST482OUTGET /favicon.ico HTTP/1.1
              Host: lionsclubs.org.au
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 17, 2024 07:45:06.633960009 CEST1289INHTTP/1.1 200 OK
              Server: Sucuri/Cloudproxy
              Date: Wed, 17 Apr 2024 05:45:06 GMT
              Content-Type: image/x-icon
              Content-Length: 1022
              Connection: keep-alive
              X-Sucuri-ID: 14006
              X-XSS-Protection: 1; mode=block
              X-Frame-Options: SAMEORIGIN
              X-Content-Type-Options: nosniff
              cache-control: max-age=315360000
              expires: Thu, 31 Dec 2037 23:55:55 GMT
              last-modified: Wed, 27 Dec 2006 04:39:45 GMT
              accept-ranges: bytes
              content-encoding: gzip
              vary: Accept-Encoding,Accept-Encoding,User-Agent
              x-turbo-charged-by: LiteSpeed
              X-Sucuri-Cache: MISS
              Data Raw: 1f 8b 08 00 00 00 00 00 00 03 dd 93 6b 54 14 44 18 86 9f 4d 34 c3 54 bc b0 a2 a9 ab 81 4a c8 45 6e c2 ba 22 cb 02 8b 0a 04 28 08 2a 2d 0a a2 40 0a 0a 69 28 20 0a 2e 24 98 19 20 48 21 82 4b 28 2d 97 95 8b 08 68 88 22 6e 96 9c 53 49 1d ef 96 76 d0 20 b5 08 d4 22 69 a1 e3 3f ff f5 af 77 ce 77 66 9e f9 e6 9c 99 6f e6 1d 10 e8 9a 81 01 43 8a 18 0e 42 5d 6f aa 8b c1 a9 19 ba 10 30 72 28 27 15 f0 52 0d 0c 0c c0 b9 47 d4 3a 40 54 92 92 42 6d 07 fa be 0a 42 dc cc 31 4c 2f 62 85 e6 22 22 33 2b ae fd d0 41 d5 f1 52 56 07 54 e2 1f b8 06 6b ab 2d c8 da 1f 32 b5 fc 3c 8b 73 8a d9 dc 7e 8f 69 8a 4c 52 83 1d 39 9c a3 25 53 32 9a 8c 7c 15 0b 37 27 20 59 ea 4e fd 8d fb b8 cd 9b ce 48 5b 0f 6e 77 3d a2 ba ae 15 c7 9a 6f 11 9d ef 26 ae f1 2b 4c 82 37 61 93 9a c3 98 ec 46 e6 44 95 60 91 5d 8e fe 89 6b c4 84 79 e2 9b 9a 41 bc eb 74 14 d1 e5 b4 68 b5 f8 5f b8 83 f1 b6 34 c4 a1 61 84 96 d6 e1 97 df ca 8c aa db 1c 51 9f 41 ee 6a 4b d1 a2 11 6c 88 8b a5 a7 fb 01 e3 d6 27 72 fa d2 0d 96 07 79 e1 70 f6 0e e6 0e b6 28 9b 2f 33 de 33 1a 59 59 1b 65 57 6e a3 48 c9 25 d1 d7 8c aa 8b 97 b0 54 b7 22 2b d0 e0 10 14 c0 72 2f 31 8f 9f f6 23 cd cc 65 d9 86 10 64 89 e9 64 c9 85 dc bd fb 13 ae 21 d1 cc 4e 2f 60 ca 91 d3 58 6f 4f 21 72 95 0b 2a 6b f0 3f d6 c0 37 5d 3d 18 b8 07 32 bb f6 3b 8e 36 9c 21 49 3c 16 a3 93 df 53 d8 f2 25 7a 4d f7 c8 b6 d7 a3 e0 ca 8f 48 0e 14 e3 bd 2f 0f c3 22 2d 63 13 55 18 9a 98 e1 11 19 8e dd a6 58 1e f7 3d c6 ac ed 3e b2 96 bb 94 a8 4b d1 5c be 4e c3 d5 5b 58 c6 ec c1 68 f7 21 bc fc 7c b0 c9 50 63 ac 6a c6 62 67 06 12 8d 16 49 6e 19 0a a7 59 cc 77 95 12 52 d3 8a 5a 02 a2 1d fb 99 5c f1 35 a2 7d 45 24 38 0b 11 47 44 f1 a0 a7 97 ce 5f ba 38 28 35 20 50 6a ce a4 b5 f1 78 a4 64 62 5a 71 89 88 f6 4e 0a db af f3 e4 c9 53 7c 74 7e 70 f1 70 c1 39 54 81 32 c8 06 61 42 31 92 b4 1c f2 24 c3 a9 e9 b8 49 a9 ba 19 61 e9 05 ec ca 2f 32 ca d2 8d 5d 12 43 7e fb a3 8f 70 b9 05 f2 bd b9 cc 54 e6 33 aa fe 1a c2 c3 a7 18 e8 ff 93 a6 9b f7 98 e0 bb 91 80 25 f6 d8 87 47 20 cd 3b 4e 95 23 24 e9 de d6 7b 6f 36 bb 57 da b3 c6 c5 04 93 63 2d 38 2b b3 30 55 b7 e1 9e 9c c6 cf 9d bf 22 52 9d a5 6c 70 ad d3 44 fa fa 7a b1 db 91 8a 63 5a 36 95 ba 1a 93 17 8c 63 e0 79 3f d5 62 08 93 cf 25 62 6b 1c 4f 9e 3d c3 71 5d 18 7e 3b 95 54 eb bc fd 7b 6f af
              Data Ascii: kTDM4TJEn"(*-@i( .$ H!K(-h"nSIv "i?wwfoCB]o0r('RG:@TBmB1L/b""3+ARVTk-2<s~iLR9%S2|7' YNH[nw=o&+L7aFD`]kyAth_4aQAjKl'ryp(/33YYeWnH%T"+r/1#edd!N/`XoO!r*k?7]=2;6!I<S%zMH/"-cUX=>K\N[Xh!|PcjbgInYwRZ\5}E$8GD_8(5 PjxdbZqNS|t~pp9T2aB1$Ia/2]C~pT3%G ;N#${o6Wc-8+0U"RlpDzcZ6cy?b%bkO=q]~;T{o
              Apr 17, 2024 07:45:06.634020090 CEST274INData Raw: ce eb 7f d3 d9 d5 cd ad ae 87 e8 6b ae 22 cd c8 e3 b9 ce ff 03 fd 7f bd fc 73 fc cf 25 18 54 cd f4 37 df 77 73 14 bc 50 d3 84 88 1d 9f ac 8e 2b 38 fd 2f 2e b1 3c 5e 96 77 6c ed d2 85 6f 0c a1 c5 07 73 d6 6c f9 d8 4f fd 5e ea 87 51 83 7c 60 cc 94
              Data Ascii: k"s%T7wsP+8/.<^wloslO^Q|`6F|VtdTOsA}Sil8_yJLs)/?xxuyw|Wu`9fX|P5T>tKUgNjZ8=`O
              Apr 17, 2024 07:45:51.641793966 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449740192.124.249.106803664C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              Apr 17, 2024 07:45:07.982923985 CEST281OUTGET /favicon.ico HTTP/1.1
              Host: lionsclubs.org.au
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Apr 17, 2024 07:45:08.819257975 CEST1289INHTTP/1.1 200 OK
              Server: Sucuri/Cloudproxy
              Date: Wed, 17 Apr 2024 05:45:08 GMT
              Content-Type: image/x-icon
              Content-Length: 1022
              Connection: keep-alive
              X-Sucuri-ID: 14006
              X-XSS-Protection: 1; mode=block
              X-Frame-Options: SAMEORIGIN
              X-Content-Type-Options: nosniff
              cache-control: max-age=315360000
              expires: Thu, 31 Dec 2037 23:55:55 GMT
              last-modified: Wed, 27 Dec 2006 04:39:45 GMT
              content-encoding: gzip
              vary: Accept-Encoding,Accept-Encoding,User-Agent
              x-turbo-charged-by: LiteSpeed
              X-Sucuri-Cache: MISS
              Accept-Ranges: bytes
              Data Raw: 1f 8b 08 00 00 00 00 00 00 03 dd 93 6b 54 14 44 18 86 9f 4d 34 c3 54 bc b0 a2 a9 ab 81 4a c8 45 6e c2 ba 22 cb 02 8b 0a 04 28 08 2a 2d 0a a2 40 0a 0a 69 28 20 0a 2e 24 98 19 20 48 21 82 4b 28 2d 97 95 8b 08 68 88 22 6e 96 9c 53 49 1d ef 96 76 d0 20 b5 08 d4 22 69 a1 e3 3f ff f5 af 77 ce 77 66 9e f9 e6 9c 99 6f e6 1d 10 e8 9a 81 01 43 8a 18 0e 42 5d 6f aa 8b c1 a9 19 ba 10 30 72 28 27 15 f0 52 0d 0c 0c c0 b9 47 d4 3a 40 54 92 92 42 6d 07 fa be 0a 42 dc cc 31 4c 2f 62 85 e6 22 22 33 2b ae fd d0 41 d5 f1 52 56 07 54 e2 1f b8 06 6b ab 2d c8 da 1f 32 b5 fc 3c 8b 73 8a d9 dc 7e 8f 69 8a 4c 52 83 1d 39 9c a3 25 53 32 9a 8c 7c 15 0b 37 27 20 59 ea 4e fd 8d fb b8 cd 9b ce 48 5b 0f 6e 77 3d a2 ba ae 15 c7 9a 6f 11 9d ef 26 ae f1 2b 4c 82 37 61 93 9a c3 98 ec 46 e6 44 95 60 91 5d 8e fe 89 6b c4 84 79 e2 9b 9a 41 bc eb 74 14 d1 e5 b4 68 b5 f8 5f b8 83 f1 b6 34 c4 a1 61 84 96 d6 e1 97 df ca 8c aa db 1c 51 9f 41 ee 6a 4b d1 a2 11 6c 88 8b a5 a7 fb 01 e3 d6 27 72 fa d2 0d 96 07 79 e1 70 f6 0e e6 0e b6 28 9b 2f 33 de 33 1a 59 59 1b 65 57 6e a3 48 c9 25 d1 d7 8c aa 8b 97 b0 54 b7 22 2b d0 e0 10 14 c0 72 2f 31 8f 9f f6 23 cd cc 65 d9 86 10 64 89 e9 64 c9 85 dc bd fb 13 ae 21 d1 cc 4e 2f 60 ca 91 d3 58 6f 4f 21 72 95 0b 2a 6b f0 3f d6 c0 37 5d 3d 18 b8 07 32 bb f6 3b 8e 36 9c 21 49 3c 16 a3 93 df 53 d8 f2 25 7a 4d f7 c8 b6 d7 a3 e0 ca 8f 48 0e 14 e3 bd 2f 0f c3 22 2d 63 13 55 18 9a 98 e1 11 19 8e dd a6 58 1e f7 3d c6 ac ed 3e b2 96 bb 94 a8 4b d1 5c be 4e c3 d5 5b 58 c6 ec c1 68 f7 21 bc fc 7c b0 c9 50 63 ac 6a c6 62 67 06 12 8d 16 49 6e 19 0a a7 59 cc 77 95 12 52 d3 8a 5a 02 a2 1d fb 99 5c f1 35 a2 7d 45 24 38 0b 11 47 44 f1 a0 a7 97 ce 5f ba 38 28 35 20 50 6a ce a4 b5 f1 78 a4 64 62 5a 71 89 88 f6 4e 0a db af f3 e4 c9 53 7c 74 7e 70 f1 70 c1 39 54 81 32 c8 06 61 42 31 92 b4 1c f2 24 c3 a9 e9 b8 49 a9 ba 19 61 e9 05 ec ca 2f 32 ca d2 8d 5d 12 43 7e fb a3 8f 70 b9 05 f2 bd b9 cc 54 e6 33 aa fe 1a c2 c3 a7 18 e8 ff 93 a6 9b f7 98 e0 bb 91 80 25 f6 d8 87 47 20 cd 3b 4e 95 23 24 e9 de d6 7b 6f 36 bb 57 da b3 c6 c5 04 93 63 2d 38 2b b3 30 55 b7 e1 9e 9c c6 cf 9d bf 22 52 9d a5 6c 70 ad d3 44 fa fa 7a b1 db 91 8a 63 5a 36 95 ba 1a 93 17 8c 63 e0 79 3f d5 62 08 93 cf 25 62 6b 1c 4f 9e 3d c3 71 5d 18 7e 3b 95 54 eb bc fd 7b 6f af
              Data Ascii: kTDM4TJEn"(*-@i( .$ H!K(-h"nSIv "i?wwfoCB]o0r('RG:@TBmB1L/b""3+ARVTk-2<s~iLR9%S2|7' YNH[nw=o&+L7aFD`]kyAth_4aQAjKl'ryp(/33YYeWnH%T"+r/1#edd!N/`XoO!r*k?7]=2;6!I<S%zMH/"-cUX=>K\N[Xh!|PcjbgInYwRZ\5}E$8GD_8(5 PjxdbZqNS|t~pp9T2aB1$Ia/2]C~pT3%G ;N#${o6Wc-8+0U"RlpDzcZ6cy?b%bkO=q]~;T{o
              Apr 17, 2024 07:45:08.819322109 CEST274INData Raw: ce eb 7f d3 d9 d5 cd ad ae 87 e8 6b ae 22 cd c8 e3 b9 ce ff 03 fd 7f bd fc 73 fc cf 25 18 54 cd f4 37 df 77 73 14 bc 50 d3 84 88 1d 9f ac 8e 2b 38 fd 2f 2e b1 3c 5e 96 77 6c ed d2 85 6f 0c a1 c5 07 73 d6 6c f9 d8 4f fd 5e ea 87 51 83 7c 60 cc 94
              Data Ascii: k"s%T7wsP+8/.<^wloslO^Q|`6F|VtdTOsA}Sil8_yJLs)/?xxuyw|Wu`9fX|P5T>tKUgNjZ8=`O
              Apr 17, 2024 07:45:53.829222918 CEST6OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44974123.55.253.34443
              TimestampBytes transferredDirectionData
              2024-04-17 05:45:08 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 05:45:08 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/073D)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=91120
              Date: Wed, 17 Apr 2024 05:45:08 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44974323.55.253.34443
              TimestampBytes transferredDirectionData
              2024-04-17 05:45:08 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 05:45:08 UTC530INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=91119
              Date: Wed, 17 Apr 2024 05:45:08 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-17 05:45:08 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:07:44:59
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:07:45:00
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2024,i,16078203422542096364,6056119984045768340,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:07:45:03
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lionsclubs.org.au/wp-content/plugins/the-events-calendar/src/resources/js/views/month-mobile-events.min.js?ver=6.3.6%5E%5E"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly