Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8

Overview

General Information

Sample URL:https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8
Analysis ID:1427661
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4108 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 480 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,349273952173196008,1665876948100521811,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.56
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.56
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8 HTTP/1.1Host: djbnrs8xv7oxi.cloudfront.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: djbnrs8xv7oxi.cloudfront.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: djbnrs8xv7oxi.cloudfront.net
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeDate: Wed, 17 Apr 2024 21:09:36 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 6bcd5dba28bbc19dcd3f4c10e978e8ee.cloudfront.net (CloudFront)X-Amz-Cf-Pop: IAD66-C2X-Amz-Cf-Id: 6PHf356MOGh6WDCFqwUuSu3pIvuGjRMu0kQdPvgdNtXtjjBkUqg7xA==
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,349273952173196008,1665876948100521811,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,349273952173196008,1665876948100521811,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
djbnrs8xv7oxi.cloudfront.net
13.32.192.19
truefalse
    high
    www.google.com
    142.250.105.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        windowsupdatebg.s.llnwi.net
        69.164.42.0
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://djbnrs8xv7oxi.cloudfront.net/favicon.icofalse
            high
            https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8false
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              13.32.192.19
              djbnrs8xv7oxi.cloudfront.netUnited States
              16509AMAZON-02USfalse
              142.250.105.105
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1427661
              Start date and time:2024-04-17 23:08:43 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 16s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/4@4/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.215.94, 64.233.185.139, 64.233.185.102, 64.233.185.138, 64.233.185.113, 64.233.185.100, 64.233.185.101, 142.250.9.84, 34.104.35.123, 40.68.123.157, 69.164.42.0, 192.229.211.108, 20.242.39.171, 13.85.23.206, 108.177.122.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 361 x 477, 8-bit colormap, non-interlaced
              Category:downloaded
              Size (bytes):91818
              Entropy (8bit):7.9923438985135276
              Encrypted:true
              SSDEEP:1536:nipdVsEO0gPPJMgOWQtzaMd+vq6HAJwHQqQRE3v+2mdK0ZHNat/jbFJ:njb0gXJMg2GY62wH36dK0ZHNGj5J
              MD5:78F1F9A97C544E02B9DBA400A3E5A730
              SHA1:9C5BB5673E9D6A03926612841FBC995781894760
              SHA-256:AC21865E1ED36B90998003BFC3F56E56EC9DDCDC023717EA1DBDC49533163459
              SHA-512:D4CEEDCD1B7046300FF642B9F9E38F0C50680ADD0D462B5CEF7D963F78238E3DE848584BEDFE4CD00954314348F72D5E38D302F7D0C968FA9445A9B521011CAF
              Malicious:false
              Reputation:low
              URL:https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8
              Preview:.PNG........IHDR...i...........x.....PLTE...j^.pe.....................ob..._XmG>.b]._V.rdyVHqND.\W.{m....i[.nbuTL.vi.l].uf...vPD...l_.....q.eY.iY...aRf=7....n\.f`.q_.g^hPJ}QKW61.i]{YO...QP.cU.dX.|n.ic.[S...yn.sd.wi`93....YO.............4**~]Q.VQyHG...v.c\.....gW.pe...lf...lb~ZI........^N....[R..y..E86}bZ.b\.....eJC.|whB:..t.......eXoSL..}..w*&&..`D?...znXIE...............-..Y>9LBA...# ..WV..{..|.....rgu]W=/.....sn.pk...sgeF0-.unP--tEH.hcp@A.yv..C%&.....mZT...vb\\...ea...nh......}ql.......FF.............x15.WN...x|.........pHYs...%...%.IR$... .IDATx...O..5.`.....8.b..2e...*Y.....M.@3S..b-.8UP.......W?E;[.Qr@.".J...<..k..m.Z..%.(.{....g<?^.....o..fO.~...xc..76.......q..[e_.V..j2...%..R._+O;.i...g..m.....s.yv....d8.j.e...;.....(.....(.22Lg.X.%.v..(....h.."55m2.Ce.4..N..j..N..n..R'YJ......y..4...\$.....\..K.r.t:.......O)x.mzaO........Cw......~..y.W.O.6.. ."..H...#a..68.T...*?.6.......fW.N....e.}.R....Uu....<.p...+.n:.7..'...,.6
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:XML 1.0 document, ASCII text
              Category:downloaded
              Size (bytes):243
              Entropy (8bit):5.4846881175554545
              Encrypted:false
              SSDEEP:6:TMVBd/ZbZjZvKtWRVzjkKRxTBifFeKT+xzWRmhjDtan:TMHd9BZKtWRHEfFVqsAhda
              MD5:42EE4ECBCB87A20D78378F0B53F538FC
              SHA1:419A2A29BFCB852397CCBD604348849B04BEF148
              SHA-256:96CBDD48EC40AA1B27FF9D844DCB9F9C7BD9D4AF657A3AB7F55E40FD49BE76BB
              SHA-512:B5F16269EBB15E3ED5F1EFBF4ACC20076196167BACF424FBE62F27FF4EAB5C7E3AA76917CF693879D38CE7C2C64FF07AD9A73802B9A6C01FD5EBC76C8A528B05
              Malicious:false
              Reputation:low
              URL:https://djbnrs8xv7oxi.cloudfront.net/favicon.ico
              Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>B8SQC8GY0304AATS</RequestId><HostId>Kvdml2ToIpUOTD1QMBS0ZVW/0eMtzq4EdQgqiB/35a0HwLlTFj4ts2dqCQq+tK8X/zrDa/Ne2QI=</HostId></Error>
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 23:09:35.866516113 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.866540909 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:35.866612911 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.866801977 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.866833925 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:35.866883993 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.866977930 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.866983891 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:35.867170095 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:35.867182970 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.114783049 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.115081072 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.115127087 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.117060900 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.117150068 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.118177891 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.118297100 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.118324995 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.124373913 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.124541044 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.124553919 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.125962019 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.126024008 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.126732111 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.126807928 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.164113045 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.167835951 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.167845011 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.215728998 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.246938944 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.247004032 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354537964 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.354594946 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354717970 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354738951 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354758024 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354798079 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354819059 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354881048 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.354881048 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.354881048 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.354898930 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.354935884 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.354940891 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.373790026 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.373858929 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.373908043 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.373927116 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.374037027 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.374037027 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.374037027 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.374067068 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.374123096 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.462044001 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.462084055 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.462135077 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.462214947 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.462234020 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.462268114 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.462274075 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.484792948 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.484882116 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.484937906 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.484963894 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.484982967 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.485013008 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.505121946 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.505193949 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.505244970 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.505275011 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.505310059 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.505326033 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.518229008 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.518424034 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.518485069 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.518589020 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.518711090 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.518711090 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.519084930 CEST49736443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.519118071 CEST4434973613.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.547060013 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.592111111 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.958107948 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.958385944 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:36.958472013 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.959223032 CEST49735443192.168.2.413.32.192.19
              Apr 17, 2024 23:09:36.959247112 CEST4434973513.32.192.19192.168.2.4
              Apr 17, 2024 23:09:38.333681107 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.333767891 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:38.333851099 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.334590912 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.334671021 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:38.565444946 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:38.565845966 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.565906048 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:38.567558050 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:38.567765951 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.971601009 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:38.972182035 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:39.014920950 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:39.014980078 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:39.054969072 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:39.545001030 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.545044899 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.545377970 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.548793077 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.548832893 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.777173996 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.777265072 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.783268929 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.783323050 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.783751011 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.836158037 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.886610031 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.932203054 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.991966009 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.992145061 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.992240906 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.992310047 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.992310047 CEST49740443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:39.992340088 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:39.992362976 CEST44349740184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.032675982 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.032756090 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.033188105 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.033698082 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.033744097 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.254218102 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.254339933 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.257074118 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.257128000 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.258157015 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.259439945 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.300189972 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.459347963 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.459516048 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.459726095 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.460264921 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.460266113 CEST49741443192.168.2.4184.31.62.93
              Apr 17, 2024 23:09:40.460329056 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:40.460364103 CEST44349741184.31.62.93192.168.2.4
              Apr 17, 2024 23:09:48.561209917 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:48.561348915 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:09:48.561568022 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:48.892915010 CEST49739443192.168.2.4142.250.105.105
              Apr 17, 2024 23:09:48.892947912 CEST44349739142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.325546026 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:38.325589895 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.325731039 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:38.325968027 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:38.325979948 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.541759014 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.587099075 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:38.587120056 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.587588072 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.588049889 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:38.588150024 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:38.633719921 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:44.383831024 CEST4972380192.168.2.423.40.205.56
              Apr 17, 2024 23:10:44.384005070 CEST4972480192.168.2.4199.232.214.172
              Apr 17, 2024 23:10:44.487931967 CEST8049724199.232.214.172192.168.2.4
              Apr 17, 2024 23:10:44.487965107 CEST8049724199.232.214.172192.168.2.4
              Apr 17, 2024 23:10:44.488071918 CEST804972323.40.205.56192.168.2.4
              Apr 17, 2024 23:10:44.488173008 CEST4972480192.168.2.4199.232.214.172
              Apr 17, 2024 23:10:44.488173008 CEST4972380192.168.2.423.40.205.56
              Apr 17, 2024 23:10:48.552141905 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:48.552294016 CEST44349750142.250.105.105192.168.2.4
              Apr 17, 2024 23:10:48.552355051 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:48.682106018 CEST49750443192.168.2.4142.250.105.105
              Apr 17, 2024 23:10:48.682138920 CEST44349750142.250.105.105192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 17, 2024 23:09:34.454178095 CEST53563181.1.1.1192.168.2.4
              Apr 17, 2024 23:09:34.475773096 CEST53582291.1.1.1192.168.2.4
              Apr 17, 2024 23:09:35.096110106 CEST53605861.1.1.1192.168.2.4
              Apr 17, 2024 23:09:35.726064920 CEST5069653192.168.2.41.1.1.1
              Apr 17, 2024 23:09:35.738363981 CEST6285753192.168.2.41.1.1.1
              Apr 17, 2024 23:09:35.851752996 CEST53506961.1.1.1192.168.2.4
              Apr 17, 2024 23:09:35.865899086 CEST53628571.1.1.1192.168.2.4
              Apr 17, 2024 23:09:38.226176977 CEST6190753192.168.2.41.1.1.1
              Apr 17, 2024 23:09:38.226300955 CEST6541653192.168.2.41.1.1.1
              Apr 17, 2024 23:09:38.331409931 CEST53654161.1.1.1192.168.2.4
              Apr 17, 2024 23:09:38.331886053 CEST53619071.1.1.1192.168.2.4
              Apr 17, 2024 23:09:52.312515974 CEST53604631.1.1.1192.168.2.4
              Apr 17, 2024 23:09:55.968590021 CEST138138192.168.2.4192.168.2.255
              Apr 17, 2024 23:10:11.396518946 CEST53527731.1.1.1192.168.2.4
              Apr 17, 2024 23:10:33.836111069 CEST53535261.1.1.1192.168.2.4
              Apr 17, 2024 23:10:34.825565100 CEST53647181.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 17, 2024 23:09:35.726064920 CEST192.168.2.41.1.1.10x34d9Standard query (0)djbnrs8xv7oxi.cloudfront.netA (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:35.738363981 CEST192.168.2.41.1.1.10x3361Standard query (0)djbnrs8xv7oxi.cloudfront.net65IN (0x0001)false
              Apr 17, 2024 23:09:38.226176977 CEST192.168.2.41.1.1.10xae42Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.226300955 CEST192.168.2.41.1.1.10x71baStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 17, 2024 23:09:35.851752996 CEST1.1.1.1192.168.2.40x34d9No error (0)djbnrs8xv7oxi.cloudfront.net13.32.192.19A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:35.851752996 CEST1.1.1.1192.168.2.40x34d9No error (0)djbnrs8xv7oxi.cloudfront.net13.32.192.137A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:35.851752996 CEST1.1.1.1192.168.2.40x34d9No error (0)djbnrs8xv7oxi.cloudfront.net13.32.192.113A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:35.851752996 CEST1.1.1.1192.168.2.40x34d9No error (0)djbnrs8xv7oxi.cloudfront.net13.32.192.91A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331409931 CEST1.1.1.1192.168.2.40x71baNo error (0)www.google.com65IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:38.331886053 CEST1.1.1.1192.168.2.40xae42No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:50.867994070 CEST1.1.1.1192.168.2.40x4daaNo error (0)windowsupdatebg.s.llnwi.net69.164.42.0A (IP address)IN (0x0001)false
              Apr 17, 2024 23:09:51.206274033 CEST1.1.1.1192.168.2.40x9977No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:09:51.206274033 CEST1.1.1.1192.168.2.40x9977No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 23:10:04.177925110 CEST1.1.1.1192.168.2.40x2242No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:10:04.177925110 CEST1.1.1.1192.168.2.40x2242No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 23:10:26.490137100 CEST1.1.1.1192.168.2.40x2a39No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:10:26.490137100 CEST1.1.1.1192.168.2.40x2a39No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 17, 2024 23:10:47.036300898 CEST1.1.1.1192.168.2.40xeefcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 17, 2024 23:10:47.036300898 CEST1.1.1.1192.168.2.40xeefcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • djbnrs8xv7oxi.cloudfront.net
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973613.32.192.19443480C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-17 21:09:36 UTC761OUTGET /neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8 HTTP/1.1
              Host: djbnrs8xv7oxi.cloudfront.net
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-17 21:09:36 UTC496INHTTP/1.1 200 OK
              Content-Type: image/png
              Content-Length: 91818
              Connection: close
              Last-Modified: Wed, 17 Apr 2024 12:00:50 GMT
              x-amz-server-side-encryption: AES256
              Accept-Ranges: bytes
              Server: AmazonS3
              Date: Wed, 17 Apr 2024 20:18:25 GMT
              ETag: "78f1f9a97c544e02b9dba400a3e5a730"
              X-Cache: Hit from cloudfront
              Via: 1.1 2af881fc3dba7aadc69b3ca00dd6e9e6.cloudfront.net (CloudFront)
              X-Amz-Cf-Pop: IAD66-C2
              X-Amz-Cf-Id: 1WjO9zw9mWm1IPAp3mMIuSrUhDvkQZAa1IXdwfO_zm7qAqMlogH90w==
              Age: 3072
              2024-04-17 21:09:36 UTC15888INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 69 00 00 01 dd 08 03 00 00 00 e8 fe 78 1f 00 00 02 01 50 4c 54 45 dd dd dd 95 6a 5e 96 70 65 d4 d3 d3 df df df e2 e2 e1 e0 e0 e1 e4 e4 e4 da da db e2 e2 e2 9b 6f 62 e7 e7 e7 8f 5f 58 6d 47 3e 93 62 5d 83 5f 56 9e 72 64 79 56 48 71 4e 44 8c 5c 57 a6 7b 6d bc 98 87 92 69 5b 90 6e 62 75 54 4c 98 76 69 8d 6c 5d a1 75 66 b6 91 80 76 50 44 d7 d7 d7 99 6c 5f be 9f 8e ac 7f 71 8d 65 59 8f 69 59 d9 d9 d9 86 61 52 66 3d 37 b7 9a 8b 93 6e 5c 94 66 60 96 71 5f 8d 67 5e 68 50 4a 7d 51 4b 57 36 31 88 69 5d 7b 59 4f c2 a9 9b 82 51 50 8a 63 55 85 64 58 a0 7c 6e 98 69 63 82 5b 53 dc c8 bc 8e 79 6e 9a 73 64 a4 77 69 60 39 33 be 88 81 80 59 4f d8 d8 d8 d8 c3 b6 b0 97 89 d0 b4 a5 e2 ce c3 34 2a 2a 7e 5d 51 86 56 51 79
              Data Ascii: PNGIHDRixPLTEj^peob_XmG>b]_VrdyVHqND\W{mi[nbuTLvil]ufvPDl_qeYiYaRf=7n\f`q_g^hPJ}QKW61i]{YOQPcUdX|nic[Synsdwi`93YO4**~]QVQy
              2024-04-17 21:09:36 UTC16384INData Raw: ea ac bf ff c6 b7 91 d8 af 8b 0b ff 2c 4c 04 48 83 ad 37 13 41 db 12 23 92 8b e8 df fe eb 8f 3f fe eb 6f 7f fb e3 8f bf fd 8d d1 74 68 21 53 24 c4 43 94 2b 32 d2 66 64 42 31 ce 1c 91 fd 03 52 27 57 57 fb 6f af ae ae 0e ae 4e de 1f bf 07 d8 ef 81 f4 9b 13 66 33 6d 7f f9 88 f4 e5 eb d7 ef 8d 56 ab c4 85 23 e9 55 d2 d4 84 74 b0 eb cd bf e1 39 b7 98 98 cf 91 de da 5a 58 72 3c 9b d3 0a 87 37 92 ad 4e 67 80 04 b1 87 1c 71 34 9c 28 e8 cb 57 2c 59 31 00 b2 24 49 12 f2 71 1b 99 22 55 07 1c c5 d1 2d 4b 91 71 a3 9e 2e 15 aa 45 5b 56 1c 49 16 8a 8a 61 0b c2 a7 1b 91 36 cd 90 de f8 f4 e9 ee 13 68 19 f0 d6 ea f5 bb 7a 3d e8 85 f6 4d fe 18 c4 33 85 73 8c 8e be c4 a6 af 9a 89 af 29 4d 44 20 c7 12 d1 e8 7f fd 2d 84 e1 8a 95 bf fd 6d e5 8f cd bd c0 97 0e b1 ec 25 fe 79 1f
              Data Ascii: ,LH7A#?oth!S$C+2fdB1R'WWoNf3mV#Ut9ZXr<7Ngq4(W,Y1$Iq"U-Kq.E[VIa6hz=M3s)MD -m%y
              2024-04-17 21:09:36 UTC16384INData Raw: 78 0b e9 ab ab 5c 39 9d 2f e7 1b 85 5c 2e 90 bb c9 5d d5 03 5b 5f bd 58 5c ec 6e 84 97 d3 b7 01 f1 7e 8b a2 0b 50 b6 a9 57 4b ee 1a 60 ce c0 91 10 62 ec 57 79 72 23 30 1c 9e 20 65 2f 7a 32 f9 16 ba 45 70 63 84 7d 41 26 5f cb c3 d0 78 da 25 61 b4 4e a6 9d 12 8e 3c 66 a3 6c 5a a3 59 f8 61 4e 36 67 34 ca 64 73 7f a6 80 5a e9 d2 e8 87 68 da b1 97 35 cd a1 63 a0 9d 9c 34 1b f1 d6 68 25 1a a5 e6 e1 43 ad 64 52 43 0c 9f c9 f0 99 7c f4 94 78 21 2b 42 9c dc 0f 67 b3 88 ec cb 78 14 45 e7 4d fe bb 46 4f 25 c8 39 8f df 2c c3 fc b3 0e e0 e0 48 c3 c0 cb e5 7c 23 17 db 5a 7c d4 89 b9 bb bb 5b e4 4d a4 1f b5 b5 44 09 59 d4 81 d7 e5 e5 e5 e5 d5 56 ae 16 2d 47 6b b5 5a 35 91 c8 dd e4 f6 0a 85 5c 2c b6 b5 f8 a2 b0 bf ec db 0f ff ce a8 cb 70 64 f9 8a db 4d 21 11 99 32 dc 74
              Data Ascii: x\9/\.][_X\n~PWK`bWyr#0 e/z2Epc}A&_x%aN<flZYaN6g4dsZh5c4h%CdRC|x!+BgxEMFO%9,H|#Z|[MDYV-GkZ5\,pdM!2t
              2024-04-17 21:09:36 UTC16384INData Raw: f0 eb 97 b7 6e 75 b6 b5 de c2 be 6e d3 0a d2 39 93 29 3f 45 fc 01 dd 91 4e 55 5a 90 5e d9 5f 2a 16 8f fd 7e 17 89 8f f0 5e 2e 67 2a 5c ed 95 f7 4c 26 b7 3d 57 c8 bb fb dc 89 4f ae 4c 8e 4a cd ed ae e4 1c e3 42 40 d2 52 8e a9 5a c5 e5 53 a7 13 96 1d 63 ae 9c 13 36 13 19 50 74 71 62 8d 98 28 65 d5 9e 80 4a c0 8a 1f 1d b5 d9 b1 b7 ba 00 f5 ba 5f 30 19 e7 8e dc c6 3a 68 80 a5 48 11 18 02 d9 06 43 73 a4 a7 14 ee 68 a0 ad 14 17 bb a9 84 8e a9 50 fb b8 6a 76 27 03 16 18 bf 8b 6d 20 2a e1 ee 5d 73 bf 07 6b 57 c4 24 2b b3 e9 e9 61 79 26 f6 67 94 41 97 e5 78 9c f3 20 ce c1 07 6d c2 e1 c8 d0 e1 9b 99 99 ae 9e 8e af fe f9 85 b2 30 8f df ef bb 71 a7 99 06 8e 1e 7d 5f 44 02 3f 3f 35 c5 c2 97 8f e9 52 fe aa 40 fa 0e 1d d5 6e e3 7e b8 78 ec 2a 53 11 3c 5c de cb b9 72 7b
              Data Ascii: nun9)?ENUZ^_*~^.g*\L&=WOLJB@RZSc6Ptqb(eJ_0:hHCshPjv'm *]skW$+ay&gAx m0q}_D??5R@n~x*S<\r{
              2024-04-17 21:09:36 UTC16384INData Raw: f7 1b c2 fe 90 37 9c c4 84 3d 72 07 28 70 57 6e f7 f7 b7 71 fd 80 73 26 0e e1 e8 51 a6 da 41 81 38 39 1e 44 1e c1 a0 d7 1e 89 c4 dd 91 cb 63 6f 20 8a ac e9 3a d0 a9 7b b7 e0 f3 a9 46 cc 91 cb 77 02 71 b5 9b 5a 16 05 f0 24 99 66 e6 b6 d6 76 5f fe 7d 62 0a fa 65 86 4e 6f df e5 cb 91 08 b2 2c 4f 9f d6 3b 20 31 79 81 b5 60 fe 58 31 c5 41 6d 2a 55 a4 16 ad 14 36 96 a2 e7 ed b6 e3 b6 a3 bf bf bf df d1 df 8f a5 f5 cf 2a 95 5f ec f6 3e 37 82 97 be e9 91 91 5e 1a 29 18 31 20 d1 44 17 8e 44 90 c8 08 57 74 47 6c 23 62 70 c0 39 e9 2c 01 60 7e 03 c8 25 a9 3f 34 49 6f f4 45 56 8c 38 ef 2c 95 62 c5 62 20 e0 aa ba 42 81 50 20 1c 0e e9 dd 06 2f 65 ca 9e dd dd 7e 4b eb 46 d0 e4 41 41 0f ce 16 ce 9d 16 8b 85 82 8f b0 6f 63 a0 29 68 c1 cf 45 dc f1 a7 b9 5f e7 9a eb 48 6b 5a
              Data Ascii: 7=r(pWnqs&QA89Dco :{FwqZ$fv_}beNo,O; 1y`X1Am*U6*_>7^)1 DDWtGl#bp9,`~%?4IoEV8,bb BP /e~KFAAoc)hE_HkZ
              2024-04-17 21:09:36 UTC10394INData Raw: 5b bf 9f 42 af c7 d1 d1 97 53 f7 6a bf e6 14 c3 f0 ad 5b 3f dc ba fa c3 70 47 47 b2 ab 2b 4c 7a 1d fe 3e 2f c4 7f fc f1 ac 70 2f 80 b7 3d de c7 8c 1c 11 07 22 53 75 34 63 8f 67 32 f6 38 12 50 7d 7d 5e 3d f6 fc 21 98 87 49 b7 88 0c 2a 23 ad 56 b5 c4 5d 2e b5 58 55 3d 37 a9 ae c2 7e 5e 49 8a da a8 3d d4 e0 0f 67 55 73 b9 f4 fa 90 5e 26 f0 42 a1 90 c1 1d 4e 7a 2f 8f 8d ad 3f 4a 1f a4 ef 6c bc 7f 7f bb 52 c9 2d 2d 2d 11 d2 b3 a6 66 e9 e0 7d 0f e9 13 d5 71 ed 5e a2 fa 9c 6d 8f 68 f3 d0 59 c0 d0 73 87 1f 54 f7 6e 54 3d 11 c1 1e 0b 0b a3 b5 da f2 d6 56 2b 57 11 67 4f dd 5b fe 54 39 eb 1d ee 80 45 ff 80 80 05 5d c9 98 fc 8e f5 79 fb d0 f1 cd 20 db 05 4d d4 13 a6 75 fa 20 c3 26 bb 8e 50 62 a4 cf 0b f2 80 53 6e a0 16 10 ce 32 e5 35 7a a6 3c 79 21 ca 2d 56 d1 58 c3
              Data Ascii: [BSj[?pGG+Lz>/p/="Su4cg28P}}^=!I*#V].XU=7~^I=gUs^&BNz/?JlR---f}q^mhYsTnT=V+WgO[T9E]y Mu &PbSn25z<y!-VX


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973513.32.192.19443480C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-17 21:09:36 UTC702OUTGET /favicon.ico HTTP/1.1
              Host: djbnrs8xv7oxi.cloudfront.net
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-17 21:09:36 UTC357INHTTP/1.1 403 Forbidden
              Content-Type: application/xml
              Transfer-Encoding: chunked
              Connection: close
              Date: Wed, 17 Apr 2024 21:09:36 GMT
              Server: AmazonS3
              X-Cache: Error from cloudfront
              Via: 1.1 6bcd5dba28bbc19dcd3f4c10e978e8ee.cloudfront.net (CloudFront)
              X-Amz-Cf-Pop: IAD66-C2
              X-Amz-Cf-Id: 6PHf356MOGh6WDCFqwUuSu3pIvuGjRMu0kQdPvgdNtXtjjBkUqg7xA==
              2024-04-17 21:09:36 UTC249INData Raw: 66 33 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 42 38 53 51 43 38 47 59 30 33 30 34 41 41 54 53 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 4b 76 64 6d 6c 32 54 6f 49 70 55 4f 54 44 31 51 4d 42 53 30 5a 56 57 2f 30 65 4d 74 7a 71 34 45 64 51 67 71 69 42 2f 33 35 61 30 48 77 4c 6c 54 46 6a 34 74 73 32 64 71 43 51 71 2b 74 4b 38 58 2f 7a 72 44 61 2f 4e 65 32 51 49 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72 72 6f 72 3e 0d 0a
              Data Ascii: f3<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>B8SQC8GY0304AATS</RequestId><HostId>Kvdml2ToIpUOTD1QMBS0ZVW/0eMtzq4EdQgqiB/35a0HwLlTFj4ts2dqCQq+tK8X/zrDa/Ne2QI=</HostId></Error>
              2024-04-17 21:09:36 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449740184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-17 21:09:39 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 21:09:39 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/079C)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=35680
              Date: Wed, 17 Apr 2024 21:09:39 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449741184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-17 21:09:40 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-17 21:09:40 UTC804INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0778)
              X-CID: 11
              X-CCC: US
              X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
              X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
              Content-Type: application/octet-stream
              X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
              Cache-Control: public, max-age=35616
              Date: Wed, 17 Apr 2024 21:09:40 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-17 21:09:40 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:23:09:31
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:23:09:32
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,349273952173196008,1665876948100521811,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:23:09:35
              Start date:17/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://djbnrs8xv7oxi.cloudfront.net/neteffekt_us/email_assets/7195/640xunlimited___screenshot_20240417_075807.png?icfid=7195-8"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly