Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$

Overview

General Information

Sample URL:https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0
Analysis ID:1428259
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2000,i,643697219029026294,11037959084248359283,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://survey.tpcdm.com/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 23.36.68.63
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.18
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.18
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$ HTTP/1.1Host: survey.tpcdm.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: survey.tpcdm.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://survey.tpcdm.com/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: survey.tpcdm.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/10.0X-Powered-By: ASP.NETDate: Thu, 18 Apr 2024 16:32:43 GMTConnection: closeContent-Length: 1245
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.36.68.63:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2000,i,643697219029026294,11037959084248359283,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2000,i,643697219029026294,11037959084248359283,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.15.99
truefalse
    high
    tpcdm.com
    169.62.14.179
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        survey.tpcdm.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://survey.tpcdm.com/favicon.icofalse
            high
            https://survey.tpcdm.com/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$false
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              169.62.14.179
              tpcdm.comUnited States
              36351SOFTLAYERUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.251.15.99
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              192.168.2.5
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1428259
              Start date and time:2024-04-18 18:31:36 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 28s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/4@4/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.215.94, 142.250.9.100, 142.250.9.139, 142.250.9.101, 142.250.9.113, 142.250.9.138, 142.250.9.102, 74.125.138.84, 34.104.35.123, 40.127.169.103, 23.47.204.64, 23.47.204.54, 23.47.204.75, 23.47.204.45, 23.47.204.73, 23.47.204.83, 23.47.204.44, 13.85.23.206, 192.229.211.108, 13.95.31.18, 172.253.124.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with very long lines (379), with CRLF line terminators
              Category:downloaded
              Size (bytes):3490
              Entropy (8bit):4.728496519121105
              Encrypted:false
              SSDEEP:96:4+3sq2ixgj/BH61acPXBJHuXohGDHuWtkX:h3sqLxgj/txiko8HT6X
              MD5:504AE2E068B4F2F58F27804A5DB9B9BA
              SHA1:15B9C0C456B6A113D34BB53C0DF25423F6DB277C
              SHA-256:F69EC9C7D598B2859AC983EF6ADB3A865E7037B097CBC06D8F32582679309483
              SHA-512:A60DACAF04B099631AC93ECF508600F4F9079A0250B2426A9BE87629AB7FD3C17CB139545D815F99B2568D582E2EB8C6366F1496FDD67480DC141A3492DA455D
              Malicious:false
              Reputation:low
              URL:https://survey.tpcdm.com/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$
              Preview:<!DOCTYPE html>..<html>.. <head>.. <title>Runtime Error</title>.. <meta name="viewport" content="width=device-width" />.. <style>.. body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} .. p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}.. b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}.. H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }.. H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }.. pre {font-family:"Consolas","Lucida Console",Monospace;font-size:11pt;margin:0;padding:0.5em;line-height:14pt}.. .marker {font-weight: bold; color: black;text-decoration: none;}.. .version {color: gray;}.. .error {margin-bottom: 10px;}.. .expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:pointer; }.. @media screen and (max-width: 639px) {..
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):1245
              Entropy (8bit):5.462849750105637
              Encrypted:false
              SSDEEP:24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
              MD5:5343C1A8B203C162A3BF3870D9F50FD4
              SHA1:04B5B886C20D88B57EEA6D8FF882624A4AC1E51D
              SHA-256:DC1D54DAB6EC8C00F70137927504E4F222C8395F10760B6BEECFCFA94E08249F
              SHA-512:E0F50ACB6061744E825A4051765CEBF23E8C489B55B190739409D8A79BB08DAC8F919247A4E5F65A015EA9C57D326BBEF7EA045163915129E01F316C4958D949
              Malicious:false
              Reputation:low
              URL:https://survey.tpcdm.com/favicon.ico
              Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>..<title>404 - File or directory not found.</title>..<style type="text/css">.. ..body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px 10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..background-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}..-->..</style>..</head>..<body>..<div id="header"><h1>Server Error</h1></div>..<div id="content">.. <div class="co
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 18, 2024 18:32:24.374232054 CEST49675443192.168.2.4173.222.162.32
              Apr 18, 2024 18:32:33.983563900 CEST49675443192.168.2.4173.222.162.32
              Apr 18, 2024 18:32:41.616355896 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.616375923 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.616465092 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.617311001 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.617352962 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.617511988 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.617687941 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.617702007 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.617990971 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.618012905 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.994813919 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.995353937 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.995382071 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.995781898 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.996154070 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.996203899 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.996619940 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.996752977 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:41.997792959 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:41.997905970 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.002249002 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.002327919 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.002510071 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.002527952 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.002717972 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.002825022 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.045126915 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.045133114 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.045164108 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.092587948 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.126317024 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.126362085 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.126434088 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.126446962 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.126498938 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.126503944 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.126583099 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.126640081 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.132540941 CEST49735443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.132556915 CEST44349735169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.319159985 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.364134073 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.438101053 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.438301086 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:42.438471079 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.448164940 CEST49736443192.168.2.4169.62.14.179
              Apr 18, 2024 18:32:42.448194027 CEST44349736169.62.14.179192.168.2.4
              Apr 18, 2024 18:32:43.444593906 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.444618940 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.444689035 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.446306944 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.446326017 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.670876026 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.705604076 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.705616951 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.709157944 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.709259987 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.725800991 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.726111889 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.779361963 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:43.779369116 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:43.826361895 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:44.519810915 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.519890070 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.520052910 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.523435116 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.523499966 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.744091988 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.744333029 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.750138998 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.750186920 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.750627041 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.798726082 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.828896046 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.876128912 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.947493076 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.947588921 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:44.948012114 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.948012114 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.948086023 CEST49740443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:44.948142052 CEST4434974023.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.036865950 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.036906004 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.037161112 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.037924051 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.037944078 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.254462004 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.254662991 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.278116941 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.278156042 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.278978109 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.280641079 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.328156948 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.460386038 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.460581064 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:45.460639954 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.463074923 CEST49741443192.168.2.423.36.68.63
              Apr 18, 2024 18:32:45.463093042 CEST4434974123.36.68.63192.168.2.4
              Apr 18, 2024 18:32:46.543252945 CEST49672443192.168.2.4173.222.162.32
              Apr 18, 2024 18:32:46.543297052 CEST44349672173.222.162.32192.168.2.4
              Apr 18, 2024 18:32:53.661047935 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:53.661196947 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:32:53.661252975 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:53.844135046 CEST49739443192.168.2.4142.251.15.99
              Apr 18, 2024 18:32:53.844173908 CEST44349739142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:38.248718977 CEST4972480192.168.2.423.40.205.18
              Apr 18, 2024 18:33:38.355206966 CEST804972423.40.205.18192.168.2.4
              Apr 18, 2024 18:33:38.355317116 CEST4972480192.168.2.423.40.205.18
              Apr 18, 2024 18:33:43.390923977 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:43.390942097 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.391055107 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:43.391242027 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:43.391248941 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.606595993 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.606908083 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:43.606925964 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.607578039 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.608078957 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:43.608181000 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:43.654874086 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:53.624587059 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:53.624746084 CEST44349750142.251.15.99192.168.2.4
              Apr 18, 2024 18:33:53.625190020 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:53.843945026 CEST49750443192.168.2.4142.251.15.99
              Apr 18, 2024 18:33:53.843983889 CEST44349750142.251.15.99192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 18, 2024 18:32:39.365102053 CEST53520781.1.1.1192.168.2.4
              Apr 18, 2024 18:32:39.368220091 CEST53529191.1.1.1192.168.2.4
              Apr 18, 2024 18:32:40.003933907 CEST53600221.1.1.1192.168.2.4
              Apr 18, 2024 18:32:41.470212936 CEST5331453192.168.2.41.1.1.1
              Apr 18, 2024 18:32:41.470494986 CEST5915053192.168.2.41.1.1.1
              Apr 18, 2024 18:32:41.613296986 CEST53591501.1.1.1192.168.2.4
              Apr 18, 2024 18:32:41.613508940 CEST53533141.1.1.1192.168.2.4
              Apr 18, 2024 18:32:43.331140995 CEST5942753192.168.2.41.1.1.1
              Apr 18, 2024 18:32:43.331990957 CEST6074753192.168.2.41.1.1.1
              Apr 18, 2024 18:32:43.436398983 CEST53594271.1.1.1192.168.2.4
              Apr 18, 2024 18:32:43.438256979 CEST53607471.1.1.1192.168.2.4
              Apr 18, 2024 18:32:49.931657076 CEST138138192.168.2.4192.168.2.255
              Apr 18, 2024 18:32:57.559989929 CEST53492101.1.1.1192.168.2.4
              Apr 18, 2024 18:33:16.365638018 CEST53532711.1.1.1192.168.2.4
              Apr 18, 2024 18:33:38.935372114 CEST53563501.1.1.1192.168.2.4
              Apr 18, 2024 18:33:39.093410015 CEST53563971.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 18, 2024 18:32:41.470212936 CEST192.168.2.41.1.1.10xf8aaStandard query (0)survey.tpcdm.comA (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:41.470494986 CEST192.168.2.41.1.1.10x392Standard query (0)survey.tpcdm.com65IN (0x0001)false
              Apr 18, 2024 18:32:43.331140995 CEST192.168.2.41.1.1.10x1dc8Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.331990957 CEST192.168.2.41.1.1.10x9791Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 18, 2024 18:32:41.613296986 CEST1.1.1.1192.168.2.40x392No error (0)survey.tpcdm.comtpcdm.comCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:32:41.613508940 CEST1.1.1.1192.168.2.40xf8aaNo error (0)survey.tpcdm.comtpcdm.comCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:32:41.613508940 CEST1.1.1.1192.168.2.40xf8aaNo error (0)tpcdm.com169.62.14.179A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.99A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.105A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.104A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.103A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.147A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.436398983 CEST1.1.1.1192.168.2.40x1dc8No error (0)www.google.com142.251.15.106A (IP address)IN (0x0001)false
              Apr 18, 2024 18:32:43.438256979 CEST1.1.1.1192.168.2.40x9791No error (0)www.google.com65IN (0x0001)false
              Apr 18, 2024 18:32:52.564291000 CEST1.1.1.1192.168.2.40xdf8dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:32:52.564291000 CEST1.1.1.1192.168.2.40xdf8dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 18, 2024 18:33:12.668287039 CEST1.1.1.1192.168.2.40xcfd0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:33:12.668287039 CEST1.1.1.1192.168.2.40xcfd0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 18, 2024 18:33:31.463546038 CEST1.1.1.1192.168.2.40x5f15No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:33:31.463546038 CEST1.1.1.1192.168.2.40x5f15No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 18, 2024 18:33:52.136287928 CEST1.1.1.1192.168.2.40x224aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 18, 2024 18:33:52.136287928 CEST1.1.1.1192.168.2.40x224aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • survey.tpcdm.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449735169.62.14.1794435104C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-18 16:32:41 UTC833OUTGET /BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$ HTTP/1.1
              Host: survey.tpcdm.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-18 16:32:42 UTC260INHTTP/1.1 500 Internal Server Error
              Cache-Control: private
              Content-Type: text/html; charset=utf-8
              Server: Microsoft-IIS/10.0
              X-AspNet-Version: 4.0.30319
              X-Powered-By: ASP.NET
              Date: Thu, 18 Apr 2024 16:32:42 GMT
              Connection: close
              Content-Length: 3490
              2024-04-18 16:32:42 UTC3490INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 20 20 20 20 3c 68 65 61 64 3e 0d 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 52 75 6e 74 69 6d 65 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 56 65 72 64 61 6e 61 22 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 6e 6f 72 6d 61 6c 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 2e 37 65 6d 3b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 20 0d 0a 20 20 20 20 20 20 20 20 20 70 20 7b
              Data Ascii: <!DOCTYPE html><html> <head> <title>Runtime Error</title> <meta name="viewport" content="width=device-width" /> <style> body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} p {


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449736169.62.14.1794435104C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-18 16:32:42 UTC762OUTGET /favicon.ico HTTP/1.1
              Host: survey.tpcdm.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://survey.tpcdm.com/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-18 16:32:42 UTC180INHTTP/1.1 404 Not Found
              Content-Type: text/html
              Server: Microsoft-IIS/10.0
              X-Powered-By: ASP.NET
              Date: Thu, 18 Apr 2024 16:32:43 GMT
              Connection: close
              Content-Length: 1245
              2024-04-18 16:32:42 UTC1245INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c
              Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/><title>404 - Fil


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974023.36.68.63443
              TimestampBytes transferredDirectionData
              2024-04-18 16:32:44 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-18 16:32:44 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0758)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=225064
              Date: Thu, 18 Apr 2024 16:32:44 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44974123.36.68.63443
              TimestampBytes transferredDirectionData
              2024-04-18 16:32:45 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-18 16:32:45 UTC531INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=225061
              Date: Thu, 18 Apr 2024 16:32:45 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-18 16:32:45 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:18:32:33
              Start date:18/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:18:32:37
              Start date:18/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2000,i,643697219029026294,11037959084248359283,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:18:32:40
              Start date:18/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://survey.tpcdm.com:443/BAFFC262AD1DA02B?L=0&rc=72FE96AB&xd=2-D4JNAR7&Log=217877326&source=0__;!!A-_UObntj2w!Vo0QGl0oBY9ZRMiZ-Vv-IopbuYMMfc2b35Ioc3KCirGwxKncFkY2TsEMBmqiT1lifs3AtKkyQILpf3suzVj0c0sd$"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly