Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6

Overview

General Information

Sample URL:https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
Analysis ID:1427670
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 7044 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2204,i,15302550918165274945,8975374887919318014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 5196 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6 HTTP/1.1Host: d.adroll.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: d.adroll.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: d.adroll.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: d.adroll.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.6:49712 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@6/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2204,i,15302550918165274945,8975374887919318014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2204,i,15302550918165274945,8975374887919318014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.com
44.232.82.158
truefalse
    high
    bg.microsoft.map.fastly.net
    199.232.214.172
    truefalse
      unknown
      www.google.com
      64.233.177.106
      truefalse
        high
        adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.com
        34.200.189.226
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            d.adroll.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://d.adroll.com/favicon.icofalse
                high
                https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6false
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  64.233.177.106
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  0.0.0.0
                  unknownunknown
                  unknownunknownfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  34.200.189.226
                  adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.comUnited States
                  14618AMAZON-AESUSfalse
                  44.232.82.158
                  adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.comUnited States
                  16509AMAZON-02USfalse
                  IP
                  192.168.2.4
                  192.168.2.6
                  Joe Sandbox version:40.0.0 Tourmaline
                  Analysis ID:1427670
                  Start date and time:2024-04-17 23:12:47 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 11s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:6
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@16/2@6/7
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 64.233.185.94, 173.194.219.138, 173.194.219.100, 173.194.219.113, 173.194.219.102, 173.194.219.139, 173.194.219.101, 172.217.215.84, 34.104.35.123, 20.114.59.183, 199.232.214.172, 192.229.211.108, 20.242.39.171, 13.95.31.18, 74.125.136.94
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • VT rate limit hit for: https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:GIF image data, version 89a, 1 x 1
                  Category:downloaded
                  Size (bytes):42
                  Entropy (8bit):2.9881439641616536
                  Encrypted:false
                  SSDEEP:3:CUXPQE/xlEy:1QEoy
                  MD5:D89746888DA2D9510B64A9F031EAECD5
                  SHA1:D5FCEB6532643D0D84FFE09C40C481ECDF59E15A
                  SHA-256:EF1955AE757C8B966C83248350331BD3A30F658CED11F387F8EBF05AB3368629
                  SHA-512:D5DA26B5D496EDB0221DF1A4057A8B0285D15592A8F8DC7016A294DF37ED335F3FDE6A2252962E0DF38B62847F8B771463A0124EF3F84299F262ED9D9D3CEE4C
                  Malicious:false
                  Reputation:low
                  URL:https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
                  Preview:GIF89a.............!.......,...........D.;
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 17, 2024 23:13:30.335455894 CEST49673443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:30.336460114 CEST49674443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:30.647953987 CEST49672443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:36.645617962 CEST44349698173.222.162.64192.168.2.6
                  Apr 17, 2024 23:13:36.645783901 CEST49698443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:37.320410013 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.320444107 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.320523024 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.320878029 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.320930004 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.320993900 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.321177006 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.321192980 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.321322918 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.321333885 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.680922031 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.681289911 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.681333065 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.682359934 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.682476997 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.682862043 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.683077097 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.683111906 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.683597088 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.683680058 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.683825016 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.683835983 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.684731007 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.684799910 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.685133934 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.685211897 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.732136011 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.733042002 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.733068943 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.777987957 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.803302050 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.803492069 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.803585052 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.804771900 CEST49705443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.804794073 CEST4434970534.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.846458912 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.892122030 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.964175940 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.964297056 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:37.964394093 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.974340916 CEST49704443192.168.2.634.200.189.226
                  Apr 17, 2024 23:13:37.974361897 CEST4434970434.200.189.226192.168.2.6
                  Apr 17, 2024 23:13:38.083853006 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.083901882 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.083995104 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.084249020 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.084260941 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.631562948 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.632893085 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.632915974 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.634499073 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.634561062 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.639779091 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.639882088 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.640255928 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.640268087 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.692997932 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.817260027 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.817367077 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.817457914 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.817925930 CEST49707443192.168.2.644.232.82.158
                  Apr 17, 2024 23:13:38.817940950 CEST4434970744.232.82.158192.168.2.6
                  Apr 17, 2024 23:13:38.862745047 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:38.862788916 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:38.862931967 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:38.863234043 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:38.863244057 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.084379911 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.084748030 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:39.084763050 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.086385965 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.086471081 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:39.087620020 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:39.087707043 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.130569935 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:39.130582094 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:39.177386999 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:39.942643881 CEST49674443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:39.942657948 CEST49673443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:40.255151033 CEST49672443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:13:40.779460907 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:40.779510975 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:40.779583931 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:40.782192945 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:40.782212019 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:40.997817993 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:40.997947931 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.011136055 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.011163950 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.011419058 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.052000046 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.160346031 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.208116055 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.268529892 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.268682003 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.268745899 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.269155979 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.269181967 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.269197941 CEST49711443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.269206047 CEST4434971123.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.308523893 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.308572054 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.308779955 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.309194088 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.309211016 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.521200895 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.521317959 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.523477077 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.523490906 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.523694992 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.525661945 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.568121910 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.729959965 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.730026960 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:41.730135918 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.749687910 CEST49712443192.168.2.623.201.212.130
                  Apr 17, 2024 23:13:41.749723911 CEST4434971223.201.212.130192.168.2.6
                  Apr 17, 2024 23:13:49.082551956 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:49.082632065 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:49.082672119 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:50.749608994 CEST49710443192.168.2.664.233.177.106
                  Apr 17, 2024 23:13:50.749656916 CEST4434971064.233.177.106192.168.2.6
                  Apr 17, 2024 23:13:56.832931995 CEST44349698173.222.162.64192.168.2.6
                  Apr 17, 2024 23:13:56.833009958 CEST49698443192.168.2.6173.222.162.64
                  Apr 17, 2024 23:14:38.807115078 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:38.807142973 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:38.807209015 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:38.807579994 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:38.807591915 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:39.025645971 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:39.025933027 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:39.025958061 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:39.027040005 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:39.027422905 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:39.027590990 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:39.067909956 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:49.045625925 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:49.045779943 CEST4434972064.233.177.106192.168.2.6
                  Apr 17, 2024 23:14:49.045855999 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:50.409224033 CEST49720443192.168.2.664.233.177.106
                  Apr 17, 2024 23:14:50.409260988 CEST4434972064.233.177.106192.168.2.6
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 17, 2024 23:13:36.297852039 CEST53654841.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:36.331877947 CEST53492981.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:36.976152897 CEST53598321.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:37.214107990 CEST5508453192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:37.214289904 CEST5848253192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:37.318594933 CEST53550841.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:37.318628073 CEST53584821.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:37.977488995 CEST5299753192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:37.977665901 CEST5900053192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:38.081865072 CEST53529971.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:38.083271027 CEST53590001.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:38.756527901 CEST6141553192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:38.756665945 CEST5715953192.168.2.61.1.1.1
                  Apr 17, 2024 23:13:38.861464977 CEST53614151.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:38.861563921 CEST53571591.1.1.1192.168.2.6
                  Apr 17, 2024 23:13:54.190316916 CEST53513431.1.1.1192.168.2.6
                  Apr 17, 2024 23:14:13.237303019 CEST53650621.1.1.1192.168.2.6
                  Apr 17, 2024 23:14:34.600461960 CEST53553641.1.1.1192.168.2.6
                  Apr 17, 2024 23:14:35.752561092 CEST53491591.1.1.1192.168.2.6
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Apr 17, 2024 23:13:37.214107990 CEST192.168.2.61.1.1.10x2eb3Standard query (0)d.adroll.comA (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:37.214289904 CEST192.168.2.61.1.1.10x74bfStandard query (0)d.adroll.com65IN (0x0001)false
                  Apr 17, 2024 23:13:37.977488995 CEST192.168.2.61.1.1.10xe3dbStandard query (0)d.adroll.comA (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:37.977665901 CEST192.168.2.61.1.1.10x768eStandard query (0)d.adroll.com65IN (0x0001)false
                  Apr 17, 2024 23:13:38.756527901 CEST192.168.2.61.1.1.10xc4ddStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.756665945 CEST192.168.2.61.1.1.10x4f5dStandard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Apr 17, 2024 23:13:37.318594933 CEST1.1.1.1192.168.2.60x2eb3No error (0)d.adroll.comadserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:13:37.318594933 CEST1.1.1.1192.168.2.60x2eb3No error (0)adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.com34.200.189.226A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:37.318594933 CEST1.1.1.1192.168.2.60x2eb3No error (0)adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.com54.80.187.149A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:37.318628073 CEST1.1.1.1192.168.2.60x74bfNo error (0)d.adroll.comadserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:13:38.081865072 CEST1.1.1.1192.168.2.60xe3dbNo error (0)d.adroll.comadserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:13:38.081865072 CEST1.1.1.1192.168.2.60xe3dbNo error (0)adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.com44.232.82.158A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.081865072 CEST1.1.1.1192.168.2.60xe3dbNo error (0)adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.com44.229.242.86A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.083271027 CEST1.1.1.1192.168.2.60x768eNo error (0)d.adroll.comadserver-vpc-alb-2-1898430250.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861464977 CEST1.1.1.1192.168.2.60xc4ddNo error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:38.861563921 CEST1.1.1.1192.168.2.60x4f5dNo error (0)www.google.com65IN (0x0001)false
                  Apr 17, 2024 23:13:51.296394110 CEST1.1.1.1192.168.2.60x61d0No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:51.296394110 CEST1.1.1.1192.168.2.60x61d0No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:13:51.707323074 CEST1.1.1.1192.168.2.60x5949No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:13:51.707323074 CEST1.1.1.1192.168.2.60x5949No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:14:04.838026047 CEST1.1.1.1192.168.2.60xc1e4No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:14:04.838026047 CEST1.1.1.1192.168.2.60xc1e4No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:14:28.332017899 CEST1.1.1.1192.168.2.60xe1b6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:14:28.332017899 CEST1.1.1.1192.168.2.60xe1b6No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 17, 2024 23:14:47.344901085 CEST1.1.1.1192.168.2.60xa810No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 17, 2024 23:14:47.344901085 CEST1.1.1.1192.168.2.60xa810No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  • d.adroll.com
                  • https:
                  • fs.microsoft.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.64970534.200.189.2264437044C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-17 21:13:37 UTC721OUTGET /ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6 HTTP/1.1
                  Host: d.adroll.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-17 21:13:37 UTC217INHTTP/1.1 200 OK
                  Date: Wed, 17 Apr 2024 21:13:37 GMT
                  Content-Type: image/gif
                  Content-Length: 42
                  Connection: close
                  Server: nginx/1.22.1
                  Cache-Control: no-transform,public,max-age=300,s-maxage=900
                  Vary: Cookie
                  2024-04-17 21:13:37 UTC42INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 ff ff ff 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 01 44 00 3b
                  Data Ascii: GIF89a!,D;


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.64970434.200.189.2264437044C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-17 21:13:37 UTC646OUTGET /favicon.ico HTTP/1.1
                  Host: d.adroll.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-17 21:13:37 UTC232INHTTP/1.1 200 OK
                  Date: Wed, 17 Apr 2024 21:13:37 GMT
                  Content-Type: image/x-icon
                  Content-Length: 0
                  Connection: close
                  Server: nginx/1.22.1
                  Last-Modified: Wed, 10 Apr 2024 10:44:59 GMT
                  ETag: "66166dab-0"
                  Accept-Ranges: bytes


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.64970744.232.82.1584437044C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-17 21:13:38 UTC347OUTGET /favicon.ico HTTP/1.1
                  Host: d.adroll.com
                  Connection: keep-alive
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: */*
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: cors
                  Sec-Fetch-Dest: empty
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-17 21:13:38 UTC232INHTTP/1.1 200 OK
                  Date: Wed, 17 Apr 2024 21:13:38 GMT
                  Content-Type: image/x-icon
                  Content-Length: 0
                  Connection: close
                  Server: nginx/1.22.1
                  Last-Modified: Wed, 10 Apr 2024 10:44:44 GMT
                  ETag: "66166d9c-0"
                  Accept-Ranges: bytes


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.64971123.201.212.130443
                  TimestampBytes transferredDirectionData
                  2024-04-17 21:13:41 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-04-17 21:13:41 UTC467INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (chd/079C)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-eus2-z1
                  Cache-Control: public, max-age=35348
                  Date: Wed, 17 Apr 2024 21:13:41 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.64971223.201.212.130443
                  TimestampBytes transferredDirectionData
                  2024-04-17 21:13:41 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-04-17 21:13:41 UTC530INHTTP/1.1 200 OK
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Content-Type: application/octet-stream
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                  Cache-Control: public, max-age=35391
                  Date: Wed, 17 Apr 2024 21:13:41 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-04-17 21:13:41 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:23:13:30
                  Start date:17/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:23:13:32
                  Start date:17/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2204,i,15302550918165274945,8975374887919318014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:23:13:36
                  Start date:17/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6"
                  Imagebase:0x7ff684c40000
                  File size:3'242'272 bytes
                  MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly