Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://17.104-168-101-28.cprapid.com/PayPal/

Overview

General Information

Sample URL:https://17.104-168-101-28.cprapid.com/PayPal/
Analysis ID:1427704
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected suspended webpage

Classification

  • System is w10x64
  • chrome.exe (PID: 2416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2076 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2540 --field-trial-handle=2516,i,11079123082264550671,1235183958604379277,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6400 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://17.104-168-101-28.cprapid.com/PayPal/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
0.0.pages.csvJoeSecurity_suspendedwebpageYara detected suspended webpageJoe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: https://17.104-168-101-28.cprapid.com/PayPal/SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
    Source: Yara matchFile source: 0.0.pages.csv, type: HTML
    Source: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgiHTTP Parser: No favicon
    Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49745 version: TLS 1.2
    Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
    Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownTCP traffic detected without corresponding DNS query: 23.201.212.130
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: global trafficHTTP traffic detected: GET /PayPal/ HTTP/1.1Host: 17.104-168-101-28.cprapid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cgi-sys/suspendedpage.cgi HTTP/1.1Host: 17.104-168-101-28.cprapid.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 17.104-168-101-28.cprapid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgiAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /cgi-sys/suspendedpage.cgi HTTP/1.1Host: 17.104-168-101-28.cprapid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgiAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
    Source: global trafficHTTP traffic detected: GET /cgi-sys/suspendedpage.cgi HTTP/1.1Host: 17.104-168-101-28.cprapid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: unknownDNS traffic detected: queries for: 17.104-168-101-28.cprapid.com
    Source: chromecache_43.2.drString found in binary or memory: http://fontawesome.com
    Source: chromecache_43.2.drString found in binary or memory: http://fontawesome.com/license
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
    Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
    Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49744 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 23.201.212.130:443 -> 192.168.2.4:49745 version: TLS 1.2
    Source: classification engineClassification label: mal48.win@16/7@8/4
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2540 --field-trial-handle=2516,i,11079123082264550671,1235183958604379277,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://17.104-168-101-28.cprapid.com/PayPal/"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2540 --field-trial-handle=2516,i,11079123082264550671,1235183958604379277,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
    Process Injection
    1
    Process Injection
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    https://17.104-168-101-28.cprapid.com/PayPal/100%SlashNextCredential Stealing type: Phishing & Social Engineering
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      74.125.138.103
      truefalse
        high
        17.104-168-101-28.cprapid.com
        104.168.101.28
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            use.fontawesome.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://17.104-168-101-28.cprapid.com/favicon.icofalse
                unknown
                https://17.104-168-101-28.cprapid.com/PayPal/true
                  unknown
                  https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgifalse
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    http://fontawesome.com/licensechromecache_43.2.drfalse
                      high
                      http://fontawesome.comchromecache_43.2.drfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        74.125.138.103
                        www.google.comUnited States
                        15169GOOGLEUSfalse
                        239.255.255.250
                        unknownReserved
                        unknownunknownfalse
                        104.168.101.28
                        17.104-168-101-28.cprapid.comUnited States
                        36352AS-COLOCROSSINGUSfalse
                        IP
                        192.168.2.4
                        Joe Sandbox version:40.0.0 Tourmaline
                        Analysis ID:1427704
                        Start date and time:2024-04-18 01:17:15 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 3m 18s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:browseurl.jbs
                        Sample URL:https://17.104-168-101-28.cprapid.com/PayPal/
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:9
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Detection:MAL
                        Classification:mal48.win@16/7@8/4
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 0
                        • Number of non-executed functions: 0
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 142.250.105.94, 74.125.136.84, 142.250.9.138, 142.250.9.139, 142.250.9.101, 142.250.9.100, 142.250.9.113, 142.250.9.102, 34.104.35.123, 104.21.27.152, 172.67.142.245, 52.165.165.26, 199.232.210.172, 20.242.39.171, 192.229.211.108
                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, use.fontawesome.com.cdn.cloudflare.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        • VT rate limit hit for: https://17.104-168-101-28.cprapid.com/PayPal/
                        No simulations
                        No context
                        No context
                        No context
                        No context
                        No context
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:Web Open Font Format (Version 2), TrueType, length 38784, version 1.0
                        Category:downloaded
                        Size (bytes):38784
                        Entropy (8bit):7.994206374899187
                        Encrypted:true
                        SSDEEP:768:rwi65rNLMpyCz/6sHgLVleua9KenzcfcoZ2RsbQEcTOtoWsjiKAwQTn2Nvqowj:ci6hxMYCz/DHgLVlu9RAl2S/yYwjiAuT
                        MD5:F9B85C9463AF7103B9B24BBBF09A06ED
                        SHA1:D28D7222BCBEB8EA701A771E85F7EFE006E62FB1
                        SHA-256:62554277D07B20C6BFAE7C6267B3198B4846F604A37D4085BF9F54C392210B56
                        SHA-512:EC17DAE646A87852E4703148CD67826D375964459D200814A29BBF13D0EC4C9F949E57D36FDFB1624AFB68E4750AB82D923BCBC4C433BEB97C3111FC6B144869
                        Malicious:false
                        Reputation:low
                        URL:https://use.fontawesome.com/releases/v5.0.6/webfonts/fa-solid-900.woff2
                        Preview:wOF2...............,.../.........................T.V..T...`..Q.6.$.....H.. ..z..A[.IqD.}".....<.........C.;..l..d&S.....Ie.M..........A.....J...G.K..b....:......2..g..U....~R.....1...s.;F...V.5.F.....O.n.q.....'e<f...i(.....Vf...4..L4f.'M..\..|..C..F.......5.Z.....e..1...2..S...........T.?...-...#O...?...\&?v... V.*..O.b..{.}.C.t.}....b2.. &.&ur'......$y!y....@.!a&$a.l.;.0.../..v.Gp.NpU\....:....X_-..)...X....C....).J.X...0^..%..7~...*f...@@..........'..hvYT....L.2....g.oL......_).yR`E......(.!.y...-.....S.P..nf...\....v...^..+#{5:+p?.'s].....|..l.+..2KSE^o......9..........qP...P.@..mE...R.p..E1....gW..*..P..I..:7.w.K.._.........;^...J..V3cm......L;..........!....>.{`....@8.S.. .'...t1dsf..^..*].@......I...B.b...........IS.9....2H.....E.Z........8`......n.H....v5...73...8I.c..h.KBE.|.4.e.M.l.Jy.v/.S.....O....r.j....'jf0........... $.)J.......G.......\. R..@P+m...s..).6w~..s...)\...l...../..x....S:pB....0..F0.q......../.xr.,{s..X .}k.......@.D...
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with very long lines (34556)
                        Category:downloaded
                        Size (bytes):34734
                        Entropy (8bit):4.756523829846464
                        Encrypted:false
                        SSDEEP:384:UT+rB31fxDjzQ6m4CrLam31bK89kQCQ/HmMIY3B1vcvCPnjQ/4A:p31fxDfQ6WyUFKQkdQ/GM933rbQ/j
                        MD5:42EAA52604673B64D6B356C2FD7F87E3
                        SHA1:6B59CB703B2D4A7A2691F13008062B46A6BC7FDB
                        SHA-256:ED0F122470C4D13D86BBABDC38046D743D0228204A56D786D2E17BD83FD358CE
                        SHA-512:CF0DD57CD2115E3AD421066DD86BD2C7BDCD33A6A0A3F7CFD1A19F4E88D274E333FC3C4FFB9E25B2A0BB72B2E63636D141E2D0F48B99C1CFE1F7F7D74F7CA69B
                        Malicious:false
                        Reputation:low
                        URL:https://use.fontawesome.com/releases/v5.0.6/css/all.css
                        Preview:/*!. * Font Awesome Free 5.0.6 by @fontawesome - http://fontawesome.com. * License - http://fontawesome.com/license (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). */..fa,.fab,.fal,.far,.fas{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:inline-block;font-style:normal;font-variant:normal;text-rendering:auto;line-height:1}.fa-lg{font-size:1.33333em;line-height:.75em;vertical-align:-.0667em}.fa-xs{font-size:.75em}.fa-sm{font-size:.875em}.fa-1x{font-size:1em}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-6x{font-size:6em}.fa-7x{font-size:7em}.fa-8x{font-size:8em}.fa-9x{font-size:9em}.fa-10x{font-size:10em}.fa-fw{text-align:center;width:1.25em}.fa-ul{list-style-type:none;margin-left:2.5em;padding-left:0}.fa-ul>li{position:relative}.fa-li{left:-2em;position:absolute;text-align:center;width:2em;line-height:inherit}.fa-border{border:.08em solid #eee;border-radius:.1em;padding:.2em .25em .15em}.fa-pull-left{float
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (4070)
                        Category:downloaded
                        Size (bytes):7652
                        Entropy (8bit):5.648286864262415
                        Encrypted:false
                        SSDEEP:192:olVZHCkA26xd3Q4JRveuTtMy47R/Ga0kVhFuPwf8Pn9wHHyJh6:QJvVGaRF8I8g
                        MD5:80D6138A8BAA1A176909B50B46FDE367
                        SHA1:9A9061E179AA4C4D2E889C41A97EC999BDF06901
                        SHA-256:9CE1F19ADDDB7AC252845D2C1FE11B1A498273264BBF3662040A7C682368522C
                        SHA-512:682E8401575BB50E625A51C4E96956B4FDA33995FDEAF14D9CFCC9A3523BE3B31B4D485B62E87862DEB9B3DA87AE3A7218349594AF4D98B4492CBF4656E1A124
                        Malicious:false
                        Reputation:low
                        URL:https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi
                        Preview:<!DOCTYPE html>.<html>. <head>. <meta http-equiv="Content-type" content="text/html; charset=utf-8">. <meta http-equiv="Cache-control" content="no-cache">. <meta http-equiv="Pragma" content="no-cache">. <meta http-equiv="Expires" content="0">. <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=1">. <title>Account Suspended</title>. <link rel="stylesheet" href="//use.fontawesome.com/releases/v5.0.6/css/all.css">. <style type="text/css">. body {. font-family: Arial, Helvetica, sans-serif;. font-size: 14px;. line-height: 1.428571429;. background-color: #ffffff;. color: #2F3230;. padding: 0;. margin: 0;. }. section {. display: block;. padding: 0;. margin: 0;. }. .container {. margin-left: auto;. margin-right: auto;. padding: 0 10px;.
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (4070)
                        Category:dropped
                        Size (bytes):7652
                        Entropy (8bit):5.648286864262415
                        Encrypted:false
                        SSDEEP:192:olVZHCkA26xd3Q4JRveuTtMy47R/Ga0kVhFuPwf8Pn9wHHyJh6:QJvVGaRF8I8g
                        MD5:80D6138A8BAA1A176909B50B46FDE367
                        SHA1:9A9061E179AA4C4D2E889C41A97EC999BDF06901
                        SHA-256:9CE1F19ADDDB7AC252845D2C1FE11B1A498273264BBF3662040A7C682368522C
                        SHA-512:682E8401575BB50E625A51C4E96956B4FDA33995FDEAF14D9CFCC9A3523BE3B31B4D485B62E87862DEB9B3DA87AE3A7218349594AF4D98B4492CBF4656E1A124
                        Malicious:false
                        Reputation:low
                        Preview:<!DOCTYPE html>.<html>. <head>. <meta http-equiv="Content-type" content="text/html; charset=utf-8">. <meta http-equiv="Cache-control" content="no-cache">. <meta http-equiv="Pragma" content="no-cache">. <meta http-equiv="Expires" content="0">. <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=1">. <title>Account Suspended</title>. <link rel="stylesheet" href="//use.fontawesome.com/releases/v5.0.6/css/all.css">. <style type="text/css">. body {. font-family: Arial, Helvetica, sans-serif;. font-size: 14px;. line-height: 1.428571429;. background-color: #ffffff;. color: #2F3230;. padding: 0;. margin: 0;. }. section {. display: block;. padding: 0;. margin: 0;. }. .container {. margin-left: auto;. margin-right: auto;. padding: 0 10px;.
                        No static file info
                        TimestampSource PortDest PortSource IPDest IP
                        Apr 18, 2024 01:18:02.938986063 CEST49675443192.168.2.4173.222.162.32
                        Apr 18, 2024 01:18:11.120862007 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.120945930 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.121190071 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.121350050 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.121385098 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.121423006 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.121428013 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.121503115 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.121948957 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.122030020 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.415731907 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.416364908 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.416423082 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.418010950 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.418247938 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.418734074 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.419358015 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.419415951 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.420907974 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.420988083 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.423182964 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.423269033 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.423361063 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.423377037 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.423623085 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.423681021 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.469058990 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.469077110 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.469146013 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.517477036 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.677017927 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.677206039 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.677478075 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.677761078 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.677761078 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.677824020 CEST44349736104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.677898884 CEST49736443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.680944920 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.724140882 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.836982965 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.844639063 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.844665051 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.844696999 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.844785929 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.844835997 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.844927073 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.845377922 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:11.845462084 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.861593962 CEST49735443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:11.861619949 CEST44349735104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.542881966 CEST49675443192.168.2.4173.222.162.32
                        Apr 18, 2024 01:18:12.621211052 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.621296883 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.621371031 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.622533083 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.622569084 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.902152061 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.902734995 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.902772903 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.903249025 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.903829098 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.903913975 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:12.904201984 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:12.948146105 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.174572945 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.174751043 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.174828053 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.230143070 CEST49741443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.230180979 CEST44349741104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.238934994 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.239012957 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.239097118 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.239566088 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.239599943 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.262842894 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.262883902 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.262953997 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.263506889 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.263534069 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.482884884 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.486378908 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.486412048 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.487956047 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.488038063 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.521660089 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.563167095 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.566063881 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.566087961 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.566747904 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.567064047 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.567423105 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.602950096 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.603394032 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.603560925 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.610025883 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.610043049 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:13.644191027 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.656893969 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:13.809046984 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.815792084 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.815817118 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.815867901 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.815901995 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.816037893 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.816052914 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.816054106 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.817953110 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:13.819709063 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.869313955 CEST49742443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:13.869350910 CEST44349742104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.007210970 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.007241011 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.007438898 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.009016991 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.009035110 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.238029957 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.238254070 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.245511055 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.245527029 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.245965004 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.297513962 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.320369959 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.368133068 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.437036037 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.437189102 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.437264919 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.437411070 CEST49744443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.437429905 CEST4434974423.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.489154100 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.489232063 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.489491940 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.491224051 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.491302967 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.598776102 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.598820925 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.599188089 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.599668026 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.599682093 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.711410046 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.711554050 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.713565111 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.713591099 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.713932037 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.715925932 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.756159067 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.878004074 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.878345966 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.878360987 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.879784107 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.879889011 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.880637884 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.880706072 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.880811930 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.880819082 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:14.922653913 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:14.933415890 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.933558941 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.933734894 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.945297003 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.945342064 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:14.945373058 CEST49745443192.168.2.423.201.212.130
                        Apr 18, 2024 01:18:14.945388079 CEST4434974523.201.212.130192.168.2.4
                        Apr 18, 2024 01:18:15.159919024 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:15.167661905 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:15.167685986 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:15.167809963 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:15.167844057 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:15.168917894 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:15.169025898 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:15.169106007 CEST49746443192.168.2.4104.168.101.28
                        Apr 18, 2024 01:18:15.169130087 CEST44349746104.168.101.28192.168.2.4
                        Apr 18, 2024 01:18:23.483326912 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:23.483458042 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:18:23.483849049 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:23.627595901 CEST49743443192.168.2.474.125.138.103
                        Apr 18, 2024 01:18:23.627656937 CEST4434974374.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.177968979 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:13.178047895 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.178138018 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:13.178514004 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:13.178550959 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.398298979 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.398561001 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:13.398614883 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.400068998 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.400373936 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:13.400567055 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:13.440382957 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:23.394582033 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:23.394747019 CEST4434975474.125.138.103192.168.2.4
                        Apr 18, 2024 01:19:23.394817114 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:23.564773083 CEST49754443192.168.2.474.125.138.103
                        Apr 18, 2024 01:19:23.564815044 CEST4434975474.125.138.103192.168.2.4
                        TimestampSource PortDest PortSource IPDest IP
                        Apr 18, 2024 01:18:09.452084064 CEST53492481.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:09.458055019 CEST53606521.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:10.091242075 CEST53496711.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:10.679193020 CEST6383453192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:10.681699038 CEST5446653192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:11.098251104 CEST53638341.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:11.120009899 CEST53544661.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:11.867242098 CEST5122153192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:11.867242098 CEST5842653192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:13.155179977 CEST5293953192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:13.155728102 CEST5204353192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:13.259820938 CEST53529391.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:13.261091948 CEST53520431.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:14.168622971 CEST6474753192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:14.169074059 CEST5864453192.168.2.41.1.1.1
                        Apr 18, 2024 01:18:14.378388882 CEST53586441.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:14.597827911 CEST53647471.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:27.028803110 CEST53546581.1.1.1192.168.2.4
                        Apr 18, 2024 01:18:29.086199045 CEST138138192.168.2.4192.168.2.255
                        Apr 18, 2024 01:18:45.997267008 CEST53639271.1.1.1192.168.2.4
                        Apr 18, 2024 01:19:08.622803926 CEST53576821.1.1.1192.168.2.4
                        Apr 18, 2024 01:19:08.769162893 CEST53529301.1.1.1192.168.2.4
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Apr 18, 2024 01:18:10.679193020 CEST192.168.2.41.1.1.10xa56bStandard query (0)17.104-168-101-28.cprapid.comA (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:10.681699038 CEST192.168.2.41.1.1.10x5c4dStandard query (0)17.104-168-101-28.cprapid.com65IN (0x0001)false
                        Apr 18, 2024 01:18:11.867242098 CEST192.168.2.41.1.1.10xa1e7Standard query (0)use.fontawesome.comA (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:11.867242098 CEST192.168.2.41.1.1.10xbf5Standard query (0)use.fontawesome.com65IN (0x0001)false
                        Apr 18, 2024 01:18:13.155179977 CEST192.168.2.41.1.1.10xf23dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.155728102 CEST192.168.2.41.1.1.10x2467Standard query (0)www.google.com65IN (0x0001)false
                        Apr 18, 2024 01:18:14.168622971 CEST192.168.2.41.1.1.10xc302Standard query (0)17.104-168-101-28.cprapid.comA (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:14.169074059 CEST192.168.2.41.1.1.10x7af3Standard query (0)17.104-168-101-28.cprapid.com65IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Apr 18, 2024 01:18:11.098251104 CEST1.1.1.1192.168.2.40xa56bNo error (0)17.104-168-101-28.cprapid.com104.168.101.28A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:11.972234964 CEST1.1.1.1192.168.2.40xa1e7No error (0)use.fontawesome.comuse.fontawesome.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:18:11.972336054 CEST1.1.1.1192.168.2.40xbf5No error (0)use.fontawesome.comuse.fontawesome.com.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.103A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.106A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.99A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.104A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.105A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.259820938 CEST1.1.1.1192.168.2.40xf23dNo error (0)www.google.com74.125.138.147A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:13.261091948 CEST1.1.1.1192.168.2.40x2467No error (0)www.google.com65IN (0x0001)false
                        Apr 18, 2024 01:18:14.597827911 CEST1.1.1.1192.168.2.40xc302No error (0)17.104-168-101-28.cprapid.com104.168.101.28A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:26.565308094 CEST1.1.1.1192.168.2.40x574aNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:26.565308094 CEST1.1.1.1192.168.2.40x574aNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:27.496589899 CEST1.1.1.1192.168.2.40xaf4dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:18:27.496589899 CEST1.1.1.1192.168.2.40xaf4dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:18:42.139090061 CEST1.1.1.1192.168.2.40xec28No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:18:42.139090061 CEST1.1.1.1192.168.2.40xec28No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:19:01.062438965 CEST1.1.1.1192.168.2.40xe661No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:19:01.062438965 CEST1.1.1.1192.168.2.40xe661No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                        Apr 18, 2024 01:19:21.513029099 CEST1.1.1.1192.168.2.40xd5b5No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                        Apr 18, 2024 01:19:21.513029099 CEST1.1.1.1192.168.2.40xd5b5No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                        • 17.104-168-101-28.cprapid.com
                        • https:
                        • fs.microsoft.com
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.449736104.168.101.284432076C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:11 UTC679OUTGET /PayPal/ HTTP/1.1
                        Host: 17.104-168-101-28.cprapid.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-04-17 23:18:11 UTC235INHTTP/1.1 302 Found
                        Date: Wed, 17 Apr 2024 23:18:11 GMT
                        Server: Apache
                        Location: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi
                        Content-Length: 247
                        Connection: close
                        Content-Type: text/html; charset=iso-8859-1
                        2024-04-17 23:18:11 UTC247INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 31 37 2e 31 30 34 2d 31 36 38 2d 31 30 31 2d 32 38 2e 63 70 72 61 70 69 64 2e 63 6f 6d 2f 63 67 69 2d 73 79 73 2f 73 75 73 70 65 6e 64 65 64 70 61 67 65 2e 63 67 69 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi">here</a>.</p></body></html>


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.449735104.168.101.284432076C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:11 UTC697OUTGET /cgi-sys/suspendedpage.cgi HTTP/1.1
                        Host: 17.104-168-101-28.cprapid.com
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-04-17 23:18:11 UTC144INHTTP/1.1 200 OK
                        Date: Wed, 17 Apr 2024 23:18:11 GMT
                        Server: Apache
                        Connection: close
                        Transfer-Encoding: chunked
                        Content-Type: text/html
                        2024-04-17 23:18:11 UTC7660INData Raw: 31 64 65 34 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 50 72 61 67 6d 61 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 45 78 70 69 72 65 73 22 20 63 6f 6e 74 65
                        Data Ascii: 1de4<!DOCTYPE html><html> <head> <meta http-equiv="Content-type" content="text/html; charset=utf-8"> <meta http-equiv="Cache-control" content="no-cache"> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Expires" conte
                        2024-04-17 23:18:11 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        2192.168.2.449741104.168.101.284432076C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:12 UTC639OUTGET /favicon.ico HTTP/1.1
                        Host: 17.104-168-101-28.cprapid.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Sec-Fetch-Site: same-origin
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-04-17 23:18:13 UTC235INHTTP/1.1 302 Found
                        Date: Wed, 17 Apr 2024 23:18:13 GMT
                        Server: Apache
                        Location: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi
                        Content-Length: 247
                        Connection: close
                        Content-Type: text/html; charset=iso-8859-1
                        2024-04-17 23:18:13 UTC247INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 31 37 2e 31 30 34 2d 31 36 38 2d 31 30 31 2d 32 38 2e 63 70 72 61 70 69 64 2e 63 6f 6d 2f 63 67 69 2d 73 79 73 2f 73 75 73 70 65 6e 64 65 64 70 61 67 65 2e 63 67 69 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi">here</a>.</p></body></html>


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        3192.168.2.449742104.168.101.284432076C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:13 UTC653OUTGET /cgi-sys/suspendedpage.cgi HTTP/1.1
                        Host: 17.104-168-101-28.cprapid.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Sec-Fetch-Site: same-origin
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://17.104-168-101-28.cprapid.com/cgi-sys/suspendedpage.cgi
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-04-17 23:18:13 UTC144INHTTP/1.1 200 OK
                        Date: Wed, 17 Apr 2024 23:18:13 GMT
                        Server: Apache
                        Connection: close
                        Transfer-Encoding: chunked
                        Content-Type: text/html
                        2024-04-17 23:18:13 UTC7660INData Raw: 31 64 65 34 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 50 72 61 67 6d 61 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 45 78 70 69 72 65 73 22 20 63 6f 6e 74 65
                        Data Ascii: 1de4<!DOCTYPE html><html> <head> <meta http-equiv="Content-type" content="text/html; charset=utf-8"> <meta http-equiv="Cache-control" content="no-cache"> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Expires" conte
                        2024-04-17 23:18:13 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        4192.168.2.44974423.201.212.130443
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:14 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-04-17 23:18:14 UTC467INHTTP/1.1 200 OK
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (chd/079C)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-eus2-z1
                        Cache-Control: public, max-age=27875
                        Date: Wed, 17 Apr 2024 23:18:14 GMT
                        Connection: close
                        X-CID: 2


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        5192.168.2.44974523.201.212.130443
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:14 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                        Range: bytes=0-2147483646
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-04-17 23:18:14 UTC530INHTTP/1.1 200 OK
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Content-Type: application/octet-stream
                        ApiVersion: Distribute 1.1
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                        Cache-Control: public, max-age=27918
                        Date: Wed, 17 Apr 2024 23:18:14 GMT
                        Content-Length: 55
                        Connection: close
                        X-CID: 2
                        2024-04-17 23:18:14 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        6192.168.2.449746104.168.101.284432076C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-04-17 23:18:14 UTC378OUTGET /cgi-sys/suspendedpage.cgi HTTP/1.1
                        Host: 17.104-168-101-28.cprapid.com
                        Connection: keep-alive
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: */*
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-04-17 23:18:15 UTC144INHTTP/1.1 200 OK
                        Date: Wed, 17 Apr 2024 23:18:15 GMT
                        Server: Apache
                        Connection: close
                        Transfer-Encoding: chunked
                        Content-Type: text/html
                        2024-04-17 23:18:15 UTC7660INData Raw: 31 64 65 34 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 50 72 61 67 6d 61 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 45 78 70 69 72 65 73 22 20 63 6f 6e 74 65
                        Data Ascii: 1de4<!DOCTYPE html><html> <head> <meta http-equiv="Content-type" content="text/html; charset=utf-8"> <meta http-equiv="Cache-control" content="no-cache"> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Expires" conte
                        2024-04-17 23:18:15 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:01:18:05
                        Start date:18/04/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:2
                        Start time:01:18:07
                        Start date:18/04/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2540 --field-trial-handle=2516,i,11079123082264550671,1235183958604379277,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:3
                        Start time:01:18:09
                        Start date:18/04/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://17.104-168-101-28.cprapid.com/PayPal/"
                        Imagebase:0x7ff76e190000
                        File size:3'242'272 bytes
                        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:true

                        No disassembly