Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D

Overview

General Information

Sample URL:https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D
Analysis ID:1428124
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2420 --field-trial-handle=2308,i,17009714448903988676,2997614534737842408,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 5432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5DHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.7:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.7:49715 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 40.119.6.228
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /template/aid_signup_welcome_verify_adg/people.png%5D HTTP/1.1Host: id-mail-assets.atlassian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: id-mail-assets.atlassian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5DAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: id-mail-assets.atlassian.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Content-Length: 578Connection: closeDate: Thu, 18 Apr 2024 13:35:39 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 ae3759c8dc48487a424a60bd577ad554.cloudfront.net (CloudFront)X-Amz-Cf-Pop: IAD89-C2X-Amz-Cf-Id: qNWQPW-Moa3wcYWUYq7tyPQg8tijOmCzhNNv9aaBqHNyAlSXZqqIFw==
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Content-Length: 539Connection: closeDate: Thu, 18 Apr 2024 13:35:39 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 8ad5a9cbb864898c238f716c1a12623c.cloudfront.net (CloudFront)X-Amz-Cf-Pop: IAD89-C2X-Amz-Cf-Id: tnJLiNfcpRScTEo7TMmnj_BEUBbiqibzMmU53VFh2waFDi7FRg4hAw==
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.7:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.7:49715 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2420 --field-trial-handle=2308,i,17009714448903988676,2997614534737842408,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2420 --field-trial-handle=2308,i,17009714448903988676,2997614534737842408,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    d1okyj5xijevyb.cloudfront.net
    99.84.191.103
    truefalse
      high
      www.google.com
      108.177.122.99
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          id-mail-assets.atlassian.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5Dfalse
              high
              https://id-mail-assets.atlassian.com/favicon.icofalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                74.125.138.105
                unknownUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                99.84.191.103
                d1okyj5xijevyb.cloudfront.netUnited States
                16509AMAZON-02USfalse
                108.177.122.99
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.7
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1428124
                Start date and time:2024-04-18 15:34:42 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 23s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:18
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/4@6/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.253.124.94, 172.217.215.100, 172.217.215.101, 172.217.215.113, 172.217.215.138, 172.217.215.139, 172.217.215.102, 64.233.177.84, 34.104.35.123, 40.127.169.103, 199.232.214.172, 192.229.211.108, 13.85.23.206, 23.47.204.78, 23.47.204.67, 23.47.204.48, 23.47.204.44, 23.47.204.72, 23.47.204.75, 23.47.204.69, 23.47.204.81, 23.47.204.79, 20.242.39.171, 23.40.205.8, 23.40.205.9, 23.40.205.51, 23.40.205.48, 23.40.205.74, 23.40.205.57, 23.40.205.49, 23.40.205.73, 23.40.205.80, 199.232.210.172, 142.250.105.94
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, time.windows.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):578
                Entropy (8bit):5.348493076757593
                Encrypted:false
                SSDEEP:12:yeRHbx5tr9HdUvqbnWic+IDWZZvS67Ig9HdUwoRRpQL:yeRHbhFbWin95731V
                MD5:98D6107D15A7060AF6458D5AB41EB574
                SHA1:FE68E2C11B966394AD09483225667C068C006317
                SHA-256:3FD44F2A82215D066231AFD065AE632A4920CFB963D48DD8D28C245773F62E1E
                SHA-512:2389D7A6E0EB34BA6F84F67449E9470C7F2739841ED66534166EFA2F3958378EBBA33B2AE3AF58700A77FCF736AA99BCD4EB7259A6036250A719381627F7A7D7
                Malicious:false
                Reputation:low
                URL:https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D
                Preview:<html>.<head><title>404 Not Found</title></head>.<body>.<h1>404 Not Found</h1>.<ul>.<li>Code: NoSuchKey</li>.<li>Message: The specified key does not exist.</li>.<li>Key: template/aid_signup_welcome_verify_adg/people.png]</li>.<li>RequestId: VJB7HRWRJF48G26H</li>.<li>HostId: QF8AzTMqO2EsTuSUEGwXgukX1MG7HmzVg9uGgpn2FdRbhksWvTg3bRSO2rf2izopfPX4gLSAF2A=</li>.</ul>.<h3>An Error Occurred While Attempting to Retrieve a Custom Error Document</h3>.<ul>.<li>Code: NoSuchKey</li>.<li>Message: The specified key does not exist.</li>.<li>Key: error.html</li>.</ul>.<hr/>.</body>.</html>.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):539
                Entropy (8bit):5.297814001767244
                Encrypted:false
                SSDEEP:12:yeRHbx5tr9HdUjzWmvqnQmCieAfvS67Ig9HdUwoRRpQL:yeRHbhU6mvUCieAn5731V
                MD5:ED9A2E217C07E34FFF95F643B8824AB3
                SHA1:A1C260A16326099B2F770B391773ACD0D2BCB735
                SHA-256:6E45E24C101E91F6E123937BA850787D443FE239EF2737D4779EA040AC8D1FF8
                SHA-512:2D67F98ABF440A554CF9AB68665B605A5CF71C8F61336B3FB3FA07EE740F9857539509C6FCB77EBCA73284CCF68D967CA01FFC1F1016D93B48A90D00C3E9E2D8
                Malicious:false
                Reputation:low
                URL:https://id-mail-assets.atlassian.com/favicon.ico
                Preview:<html>.<head><title>404 Not Found</title></head>.<body>.<h1>404 Not Found</h1>.<ul>.<li>Code: NoSuchKey</li>.<li>Message: The specified key does not exist.</li>.<li>Key: favicon.ico</li>.<li>RequestId: VJBFTA70FESRDQ6E</li>.<li>HostId: xl0Wgar+PeJJ7nJR5ZFb00tOQOxHo5KoxjoJRmbxJAYNmwMnPa5pLB4WbyQjVc6nHvRhtKIXy0A=</li>.</ul>.<h3>An Error Occurred While Attempting to Retrieve a Custom Error Document</h3>.<ul>.<li>Code: NoSuchKey</li>.<li>Message: The specified key does not exist.</li>.<li>Key: error.html</li>.</ul>.<hr/>.</body>.</html>.
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 18, 2024 15:35:30.903300047 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:31.199518919 CEST49674443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:31.199637890 CEST49675443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:31.215135098 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:31.246439934 CEST49672443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:31.824551105 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:33.027779102 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:35.433922052 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:39.450246096 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:39.898163080 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.898250103 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:39.898329020 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.898680925 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.898734093 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:39.898786068 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.899092913 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.899111986 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:39.899456978 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:39.899512053 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:39.921539068 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:40.150150061 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.150434017 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.150475025 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.150844097 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.150912046 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.151556015 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.151597023 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.153510094 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.154009104 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.154033899 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.154268026 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.154350042 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.154413939 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.154480934 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.154771090 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.154781103 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.155108929 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.155143023 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.163526058 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.163611889 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.334259033 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.334261894 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:40.334273100 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.334312916 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.424374104 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.424505949 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.424592018 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.425287962 CEST49709443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.425317049 CEST4434970999.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.483994961 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.508440971 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.556118965 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.668490887 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.668589115 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.668664932 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.669358015 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:40.691442966 CEST49708443192.168.2.799.84.191.103
                Apr 18, 2024 15:35:40.691482067 CEST4434970899.84.191.103192.168.2.7
                Apr 18, 2024 15:35:40.813919067 CEST49674443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:40.816284895 CEST49675443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:40.887828112 CEST49672443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:41.126838923 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.126888037 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.127263069 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.127485991 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.127500057 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.346504927 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.347059011 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.347074986 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.348069906 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.348242998 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.349307060 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.349369049 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.402790070 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:41.402816057 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:41.449914932 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:42.168579102 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:42.227658987 CEST44349701104.98.116.138192.168.2.7
                Apr 18, 2024 15:35:42.227747917 CEST49701443192.168.2.7104.98.116.138
                Apr 18, 2024 15:35:43.283066034 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.283129930 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.284408092 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.315367937 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.315387011 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.533493996 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.533648968 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.541537046 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.541548014 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.541881084 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.590429068 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.697113991 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.744116068 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.801783085 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.801851034 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.802201033 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.802226067 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.802242994 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.802242994 CEST49714443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.802251101 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.802257061 CEST44349714184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.886835098 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.886881113 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:43.887742996 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.897963047 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:43.897996902 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.110141039 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.110255003 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:44.125304937 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:44.125324011 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.125667095 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.128223896 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:44.172136068 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.316883087 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.316955090 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:44.317030907 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:44.411824942 CEST49715443192.168.2.7184.31.62.93
                Apr 18, 2024 15:35:44.411861897 CEST44349715184.31.62.93192.168.2.7
                Apr 18, 2024 15:35:45.153534889 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:49.934834957 CEST49671443192.168.2.7204.79.197.203
                Apr 18, 2024 15:35:51.122102976 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:35:51.365616083 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:51.365685940 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:35:51.365740061 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:52.734791994 CEST49712443192.168.2.7108.177.122.99
                Apr 18, 2024 15:35:52.734816074 CEST44349712108.177.122.99192.168.2.7
                Apr 18, 2024 15:36:03.028822899 CEST49677443192.168.2.720.50.201.200
                Apr 18, 2024 15:36:41.666695118 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:41.666752100 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:41.666841030 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:41.667478085 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:41.667494059 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:41.880151033 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:41.921961069 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:41.921981096 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:41.922521114 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:41.961711884 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:41.961889982 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:42.012640953 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:51.878186941 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:51.878264904 CEST4434972574.125.138.105192.168.2.7
                Apr 18, 2024 15:36:51.878309011 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:52.869568110 CEST49725443192.168.2.774.125.138.105
                Apr 18, 2024 15:36:52.869600058 CEST4434972574.125.138.105192.168.2.7
                TimestampSource PortDest PortSource IPDest IP
                Apr 18, 2024 15:35:38.559823990 CEST53626271.1.1.1192.168.2.7
                Apr 18, 2024 15:35:38.566875935 CEST53564931.1.1.1192.168.2.7
                Apr 18, 2024 15:35:39.161715984 CEST53635591.1.1.1192.168.2.7
                Apr 18, 2024 15:35:39.765985966 CEST6498453192.168.2.71.1.1.1
                Apr 18, 2024 15:35:39.766140938 CEST6199153192.168.2.71.1.1.1
                Apr 18, 2024 15:35:39.874789000 CEST53619911.1.1.1192.168.2.7
                Apr 18, 2024 15:35:39.897294044 CEST53649841.1.1.1192.168.2.7
                Apr 18, 2024 15:35:41.020687103 CEST5340053192.168.2.71.1.1.1
                Apr 18, 2024 15:35:41.020961046 CEST5235053192.168.2.71.1.1.1
                Apr 18, 2024 15:35:41.125200987 CEST53534001.1.1.1192.168.2.7
                Apr 18, 2024 15:35:41.125248909 CEST53523501.1.1.1192.168.2.7
                Apr 18, 2024 15:35:46.045638084 CEST123123192.168.2.740.119.6.228
                Apr 18, 2024 15:35:46.179248095 CEST12312340.119.6.228192.168.2.7
                Apr 18, 2024 15:35:56.892206907 CEST53616431.1.1.1192.168.2.7
                Apr 18, 2024 15:36:15.714772940 CEST53579041.1.1.1192.168.2.7
                Apr 18, 2024 15:36:37.682987928 CEST53654861.1.1.1192.168.2.7
                Apr 18, 2024 15:36:38.399337053 CEST53621671.1.1.1192.168.2.7
                Apr 18, 2024 15:36:39.949074030 CEST138138192.168.2.7192.168.2.255
                Apr 18, 2024 15:36:41.559880972 CEST5918453192.168.2.71.1.1.1
                Apr 18, 2024 15:36:41.560121059 CEST5501553192.168.2.71.1.1.1
                Apr 18, 2024 15:36:41.664469004 CEST53591841.1.1.1192.168.2.7
                Apr 18, 2024 15:36:41.664670944 CEST53550151.1.1.1192.168.2.7
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 18, 2024 15:35:39.765985966 CEST192.168.2.71.1.1.10xa23fStandard query (0)id-mail-assets.atlassian.comA (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:39.766140938 CEST192.168.2.71.1.1.10x8544Standard query (0)id-mail-assets.atlassian.com65IN (0x0001)false
                Apr 18, 2024 15:35:41.020687103 CEST192.168.2.71.1.1.10x9656Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.020961046 CEST192.168.2.71.1.1.10xcc18Standard query (0)www.google.com65IN (0x0001)false
                Apr 18, 2024 15:36:41.559880972 CEST192.168.2.71.1.1.10x7bf1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.560121059 CEST192.168.2.71.1.1.10x8fddStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 18, 2024 15:35:39.874789000 CEST1.1.1.1192.168.2.70x8544No error (0)id-mail-assets.atlassian.comid-mail-assets.prod.atl-paas.netCNAME (Canonical name)IN (0x0001)false
                Apr 18, 2024 15:35:39.874789000 CEST1.1.1.1192.168.2.70x8544No error (0)id-mail-assets.prod.atl-paas.netd1okyj5xijevyb.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)id-mail-assets.atlassian.comid-mail-assets.prod.atl-paas.netCNAME (Canonical name)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)id-mail-assets.prod.atl-paas.netd1okyj5xijevyb.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)d1okyj5xijevyb.cloudfront.net99.84.191.103A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)d1okyj5xijevyb.cloudfront.net99.84.191.128A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)d1okyj5xijevyb.cloudfront.net99.84.191.25A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:39.897294044 CEST1.1.1.1192.168.2.70xa23fNo error (0)d1okyj5xijevyb.cloudfront.net99.84.191.4A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.99A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.147A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.105A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.104A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.103A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125200987 CEST1.1.1.1192.168.2.70x9656No error (0)www.google.com108.177.122.106A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:41.125248909 CEST1.1.1.1192.168.2.70xcc18No error (0)www.google.com65IN (0x0001)false
                Apr 18, 2024 15:35:52.097522020 CEST1.1.1.1192.168.2.70xe096No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 18, 2024 15:35:52.097522020 CEST1.1.1.1192.168.2.70xe096No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:52.111712933 CEST1.1.1.1192.168.2.70x3612No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 18, 2024 15:35:52.111712933 CEST1.1.1.1192.168.2.70x3612No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:31.324736118 CEST1.1.1.1192.168.2.70x4528No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:31.324736118 CEST1.1.1.1192.168.2.70x4528No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.105A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.147A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.103A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.106A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.104A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664469004 CEST1.1.1.1192.168.2.70x7bf1No error (0)www.google.com74.125.138.99A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:41.664670944 CEST1.1.1.1192.168.2.70x8fddNo error (0)www.google.com65IN (0x0001)false
                Apr 18, 2024 15:36:50.425921917 CEST1.1.1.1192.168.2.70x1062No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 18, 2024 15:36:50.425921917 CEST1.1.1.1192.168.2.70x1062No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                • id-mail-assets.atlassian.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.74970999.84.191.1034436328C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-18 13:35:40 UTC723OUTGET /template/aid_signup_welcome_verify_adg/people.png%5D HTTP/1.1
                Host: id-mail-assets.atlassian.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-18 13:35:40 UTC359INHTTP/1.1 404 Not Found
                Content-Type: text/html; charset=utf-8
                Content-Length: 578
                Connection: close
                Date: Thu, 18 Apr 2024 13:35:39 GMT
                Server: AmazonS3
                X-Cache: Error from cloudfront
                Via: 1.1 ae3759c8dc48487a424a60bd577ad554.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: IAD89-C2
                X-Amz-Cf-Id: qNWQPW-Moa3wcYWUYq7tyPQg8tijOmCzhNNv9aaBqHNyAlSXZqqIFw==
                2024-04-18 13:35:40 UTC578INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 75 6c 3e 0a 3c 6c 69 3e 43 6f 64 65 3a 20 4e 6f 53 75 63 68 4b 65 79 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4d 65 73 73 61 67 65 3a 20 54 68 65 20 73 70 65 63 69 66 69 65 64 20 6b 65 79 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4b 65 79 3a 20 74 65 6d 70 6c 61 74 65 2f 61 69 64 5f 73 69 67 6e 75 70 5f 77 65 6c 63 6f 6d 65 5f 76 65 72 69 66 79 5f 61 64 67 2f 70 65 6f 70 6c 65 2e 70 6e 67 5d 3c 2f 6c 69 3e 0a 3c 6c 69 3e 52 65 71 75 65 73 74 49 64 3a 20 56 4a 42 37 48 52 57 52 4a 46 34 38 47 32
                Data Ascii: <html><head><title>404 Not Found</title></head><body><h1>404 Not Found</h1><ul><li>Code: NoSuchKey</li><li>Message: The specified key does not exist.</li><li>Key: template/aid_signup_welcome_verify_adg/people.png]</li><li>RequestId: VJB7HRWRJF48G2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.74970899.84.191.1034436328C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-18 13:35:40 UTC664OUTGET /favicon.ico HTTP/1.1
                Host: id-mail-assets.atlassian.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-18 13:35:40 UTC359INHTTP/1.1 404 Not Found
                Content-Type: text/html; charset=utf-8
                Content-Length: 539
                Connection: close
                Date: Thu, 18 Apr 2024 13:35:39 GMT
                Server: AmazonS3
                X-Cache: Error from cloudfront
                Via: 1.1 8ad5a9cbb864898c238f716c1a12623c.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: IAD89-C2
                X-Amz-Cf-Id: tnJLiNfcpRScTEo7TMmnj_BEUBbiqibzMmU53VFh2waFDi7FRg4hAw==
                2024-04-18 13:35:40 UTC539INData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 75 6c 3e 0a 3c 6c 69 3e 43 6f 64 65 3a 20 4e 6f 53 75 63 68 4b 65 79 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4d 65 73 73 61 67 65 3a 20 54 68 65 20 73 70 65 63 69 66 69 65 64 20 6b 65 79 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4b 65 79 3a 20 66 61 76 69 63 6f 6e 2e 69 63 6f 3c 2f 6c 69 3e 0a 3c 6c 69 3e 52 65 71 75 65 73 74 49 64 3a 20 56 4a 42 46 54 41 37 30 46 45 53 52 44 51 36 45 3c 2f 6c 69 3e 0a 3c 6c 69 3e 48 6f 73 74 49 64 3a 20 78 6c 30 57 67 61 72 2b 50 65 4a 4a 37 6e 4a 52 35 5a 46
                Data Ascii: <html><head><title>404 Not Found</title></head><body><h1>404 Not Found</h1><ul><li>Code: NoSuchKey</li><li>Message: The specified key does not exist.</li><li>Key: favicon.ico</li><li>RequestId: VJBFTA70FESRDQ6E</li><li>HostId: xl0Wgar+PeJJ7nJR5ZF


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.749714184.31.62.93443
                TimestampBytes transferredDirectionData
                2024-04-18 13:35:43 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-18 13:35:43 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/079C)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=235658
                Date: Thu, 18 Apr 2024 13:35:43 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.749715184.31.62.93443
                TimestampBytes transferredDirectionData
                2024-04-18 13:35:44 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-18 13:35:44 UTC805INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/0778)
                X-CID: 11
                X-CCC: US
                X-Azure-Ref-OriginShield: Ref A: 52EA27DBDE0C4533B819423583F6692E Ref B: CH1AA2040902052 Ref C: 2023-07-09T23:10:08Z
                X-MSEdge-Ref: Ref A: 528BB8D443C042AA9AEA4EC3F75C7762 Ref B: CHI30EDGE0111 Ref C: 2023-07-09T23:11:11Z
                Content-Type: application/octet-stream
                X-Azure-Ref: 01uvbYwAAAACkqWtaEMjWQL/4cpisZkorTUVNMzBFREdFMDgxMQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                Cache-Control: public, max-age=235678
                Date: Thu, 18 Apr 2024 13:35:44 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-18 13:35:44 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:15:35:32
                Start date:18/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:15:35:35
                Start date:18/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2420 --field-trial-handle=2308,i,17009714448903988676,2997614534737842408,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:5
                Start time:15:35:38
                Start date:18/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://id-mail-assets.atlassian.com/template/aid_signup_welcome_verify_adg/people.png%5D"
                Imagebase:0x7ff6c4390000
                File size:3'242'272 bytes
                MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly