Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html

Overview

General Information

Sample URL:http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
Analysis ID:1428458
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2056 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4144 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=2212,i,4724009423031868546,16661224601431264190,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.44.104.130
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html HTTP/1.1Host: cslseqirus.com.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: cslseqirus.com.auConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NSC_JOra11xob1bq0rlcpeqchyc50zbpset=ffffffffaf1c1f1a45525d5f4f58455e445a4a42378b
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.cslseqirus.com.auConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://cslseqirus.com.au/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html HTTP/1.1Host: cslseqirus.com.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: cslseqirus.com.au
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlX-Frame-Options: SAMEORIGINCSL-Asset: PW102Date: Thu, 18 Apr 2024 22:30:24 GMTContent-Length: 1245Strict-Transport-Security: max-age=157680000Set-Cookie: NSC_JOmrp15jeaeqsxwbccac2kct5r4yjbf=ffffffffaf1c1f1a45525d5f4f58455e445a4a42378b;Version=1;path=/;secure;httponly
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.44.104.130:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/2@8/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=2212,i,4724009423031868546,16661224601431264190,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=2212,i,4724009423031868546,16661224601431264190,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
cslseqirus.com.au
12.3.33.229
truefalse
    unknown
    www.google.com
    142.250.105.147
    truefalse
      high
      www.cslseqirus.com.au
      12.3.33.229
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          windowsupdatebg.s.llnwi.net
          69.164.42.0
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://www.cslseqirus.com.au/favicon.icofalse
              unknown
              http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.htmlfalse
                unknown
                https://cslseqirus.com.au/favicon.icofalse
                  unknown
                  https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.htmlfalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    12.3.33.229
                    cslseqirus.com.auUnited States
                    17033CSL-BEHRINGUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.250.105.147
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1428458
                    Start date and time:2024-04-19 00:29:26 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 12s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:9
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean0.win@17/2@8/4
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 172.253.124.94, 74.125.138.138, 74.125.138.102, 74.125.138.101, 74.125.138.139, 74.125.138.100, 74.125.138.113, 173.194.219.84, 34.104.35.123, 13.85.23.86, 69.164.42.0, 192.229.211.108, 52.165.164.15, 142.250.105.94
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:HTML document, ASCII text, with very long lines (379), with CRLF line terminators
                    Category:downloaded
                    Size (bytes):3420
                    Entropy (8bit):4.770180438067068
                    Encrypted:false
                    SSDEEP:96:4+3sq2exgj/BH61acPXBJHuXghGDHuWtkR:h3sqJxgj/txikg8HT6R
                    MD5:0F7CCE9368A5285559D7EF3E641F18A4
                    SHA1:0E25DA9ABEC63112710CAEB14123215D24A84876
                    SHA-256:BC1832CD33B67E74FE000BDBCADB002EB3B6D47F403CD56972545898474EAF0F
                    SHA-512:7602E887F299D9A5CC35844755AB7F2012CA782B2ADCC489DB28CF3B9F7540D6D800139B92CCC3475933890CD36F1BB576B5CAE5E5437C99D8B16DCDD15B1F30
                    Malicious:false
                    Reputation:low
                    URL:https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
                    Preview:<!DOCTYPE html>..<html>.. <head>.. <title>Runtime Error</title>.. <meta name="viewport" content="width=device-width" />.. <style>.. body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} .. p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}.. b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}.. H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }.. H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }.. pre {font-family:"Consolas","Lucida Console",Monospace;font-size:11pt;margin:0;padding:0.5em;line-height:14pt}.. .marker {font-weight: bold; color: black;text-decoration: none;}.. .version {color: gray;}.. .error {margin-bottom: 10px;}.. .expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }.. @media screen and (max-width: 639px) {..
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 19, 2024 00:30:12.711508989 CEST49675443192.168.2.4173.222.162.32
                    Apr 19, 2024 00:30:21.657614946 CEST4973580192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.693671942 CEST4973680192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.694159031 CEST4973780192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.784523010 CEST804973512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:21.784804106 CEST4973580192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.784804106 CEST4973580192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.818844080 CEST804973612.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:21.818955898 CEST4973680192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.819120884 CEST804973712.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:21.819232941 CEST4973780192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.913495064 CEST804973512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:21.913723946 CEST4973580192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:21.913995981 CEST4973580192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.040754080 CEST804973512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.054824114 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.054899931 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.055041075 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.055284023 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.055320978 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.322382927 CEST49675443192.168.2.4173.222.162.32
                    Apr 19, 2024 00:30:22.588891029 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.590435028 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.590452909 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.592133999 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.592200994 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.595366955 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.595458031 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.596195936 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.596205950 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.649009943 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.732294083 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.732373953 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.732438087 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.732459068 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.732506037 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.732564926 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:22.732671976 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.803172112 CEST49740443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:22.803208113 CEST4434974012.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.152861118 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.152940989 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.153049946 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.169051886 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.169090986 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.436909914 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.437237024 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.437294006 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.438450098 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.439146042 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.439332962 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.439590931 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.480159044 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.692996979 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.693183899 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.693238974 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.693435907 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.693480968 CEST4434974112.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:23.693509102 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:23.693550110 CEST49741443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.066808939 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.066906929 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.067429066 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.070878983 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.070914030 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.073512077 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.073566914 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.073633909 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.073822021 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.073832035 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.259675026 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.259763002 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.259929895 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.260340929 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.260377884 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.288140059 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.288253069 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.294152975 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.294177055 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.294476032 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.298799038 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.306096077 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.306128979 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.307706118 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.307806015 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.327997923 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.328471899 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.335449934 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.382345915 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.382380009 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:24.429213047 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:24.497200012 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.544118881 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.604291916 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.604433060 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.604501009 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.605211973 CEST49742443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.605248928 CEST4434974223.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.669632912 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.669699907 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.670049906 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.670763016 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.670799971 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.773726940 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.778089046 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.778150082 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.779721975 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.779822111 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.790251017 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.790390015 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.807533026 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.807573080 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.851083994 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.887713909 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.887809992 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.890367985 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.890397072 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.890641928 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.892508984 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:24.940125942 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:24.946386099 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.946475029 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:24.946528912 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.980530024 CEST49745443192.168.2.412.3.33.229
                    Apr 19, 2024 00:30:24.980560064 CEST4434974512.3.33.229192.168.2.4
                    Apr 19, 2024 00:30:25.101613045 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:25.101696014 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:25.101780891 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:25.117870092 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:25.117913961 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:25.117938995 CEST49746443192.168.2.423.44.104.130
                    Apr 19, 2024 00:30:25.117954969 CEST4434974623.44.104.130192.168.2.4
                    Apr 19, 2024 00:30:34.308934927 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:34.309065104 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:30:34.309633017 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:35.780338049 CEST49743443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:30:35.780358076 CEST44349743142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:06.820270061 CEST4973680192.168.2.412.3.33.229
                    Apr 19, 2024 00:31:06.820349932 CEST4973780192.168.2.412.3.33.229
                    Apr 19, 2024 00:31:06.947119951 CEST804973612.3.33.229192.168.2.4
                    Apr 19, 2024 00:31:06.947135925 CEST804973712.3.33.229192.168.2.4
                    Apr 19, 2024 00:31:23.673290014 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:23.673347950 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.673448086 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:23.673784971 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:23.673818111 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.890818119 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.891060114 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:23.891084909 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.891554117 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.891834974 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:23.891925097 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:23.945254087 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:28.257961035 CEST4972380192.168.2.4199.232.210.172
                    Apr 19, 2024 00:31:28.258034945 CEST4972480192.168.2.4199.232.210.172
                    Apr 19, 2024 00:31:28.361727953 CEST8049723199.232.210.172192.168.2.4
                    Apr 19, 2024 00:31:28.361778975 CEST8049723199.232.210.172192.168.2.4
                    Apr 19, 2024 00:31:28.361834049 CEST8049724199.232.210.172192.168.2.4
                    Apr 19, 2024 00:31:28.361845970 CEST4972380192.168.2.4199.232.210.172
                    Apr 19, 2024 00:31:28.361867905 CEST8049724199.232.210.172192.168.2.4
                    Apr 19, 2024 00:31:28.361931086 CEST4972480192.168.2.4199.232.210.172
                    Apr 19, 2024 00:31:33.901386023 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:33.901530027 CEST44349755142.250.105.147192.168.2.4
                    Apr 19, 2024 00:31:33.901614904 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:34.155297995 CEST49755443192.168.2.4142.250.105.147
                    Apr 19, 2024 00:31:34.155344963 CEST44349755142.250.105.147192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 19, 2024 00:30:19.595082998 CEST53561121.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:19.609596968 CEST53598391.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:20.214793921 CEST53602951.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:21.427699089 CEST5938653192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:21.429424047 CEST5553353192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:21.639936924 CEST53593861.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:21.656923056 CEST53555331.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:21.916507959 CEST6180353192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:21.916718006 CEST5423653192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:22.024039030 CEST53618031.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:22.115513086 CEST53542361.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:23.622623920 CEST6408353192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:23.623051882 CEST4927553192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:23.727089882 CEST53640831.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:23.727786064 CEST53492751.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:24.075572014 CEST5374753192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:24.075974941 CEST5296253192.168.2.41.1.1.1
                    Apr 19, 2024 00:30:24.202313900 CEST53537471.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:24.305354118 CEST53529621.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:37.318084955 CEST53567891.1.1.1192.168.2.4
                    Apr 19, 2024 00:30:39.841315985 CEST138138192.168.2.4192.168.2.255
                    Apr 19, 2024 00:30:56.354433060 CEST53594621.1.1.1192.168.2.4
                    Apr 19, 2024 00:31:18.973500967 CEST53509541.1.1.1192.168.2.4
                    Apr 19, 2024 00:31:19.208291054 CEST53578371.1.1.1192.168.2.4
                    TimestampSource IPDest IPChecksumCodeType
                    Apr 19, 2024 00:30:22.115624905 CEST192.168.2.41.1.1.1c23e(Port unreachable)Destination Unreachable
                    Apr 19, 2024 00:30:24.305459023 CEST192.168.2.41.1.1.1c242(Port unreachable)Destination Unreachable
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 19, 2024 00:30:21.427699089 CEST192.168.2.41.1.1.10x6fdStandard query (0)cslseqirus.com.auA (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:21.429424047 CEST192.168.2.41.1.1.10xdaedStandard query (0)cslseqirus.com.au65IN (0x0001)false
                    Apr 19, 2024 00:30:21.916507959 CEST192.168.2.41.1.1.10xdbc9Standard query (0)cslseqirus.com.auA (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:21.916718006 CEST192.168.2.41.1.1.10x55caStandard query (0)cslseqirus.com.au65IN (0x0001)false
                    Apr 19, 2024 00:30:23.622623920 CEST192.168.2.41.1.1.10x3251Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.623051882 CEST192.168.2.41.1.1.10x119dStandard query (0)www.google.com65IN (0x0001)false
                    Apr 19, 2024 00:30:24.075572014 CEST192.168.2.41.1.1.10xd6eaStandard query (0)www.cslseqirus.com.auA (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:24.075974941 CEST192.168.2.41.1.1.10x6681Standard query (0)www.cslseqirus.com.au65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 19, 2024 00:30:21.639936924 CEST1.1.1.1192.168.2.40x6fdNo error (0)cslseqirus.com.au12.3.33.229A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:22.024039030 CEST1.1.1.1192.168.2.40xdbc9No error (0)cslseqirus.com.au12.3.33.229A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727089882 CEST1.1.1.1192.168.2.40x3251No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:23.727786064 CEST1.1.1.1192.168.2.40x119dNo error (0)www.google.com65IN (0x0001)false
                    Apr 19, 2024 00:30:24.202313900 CEST1.1.1.1192.168.2.40xd6eaNo error (0)www.cslseqirus.com.au12.3.33.229A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:36.142927885 CEST1.1.1.1192.168.2.40xb1eeNo error (0)windowsupdatebg.s.llnwi.net69.164.42.0A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:37.600856066 CEST1.1.1.1192.168.2.40x6841No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 19, 2024 00:30:37.600856066 CEST1.1.1.1192.168.2.40x6841No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:30:50.072417974 CEST1.1.1.1192.168.2.40x2126No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 19, 2024 00:30:50.072417974 CEST1.1.1.1192.168.2.40x2126No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:31:11.457290888 CEST1.1.1.1192.168.2.40x512No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 19, 2024 00:31:11.457290888 CEST1.1.1.1192.168.2.40x512No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 19, 2024 00:31:31.957247972 CEST1.1.1.1192.168.2.40xa24No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 19, 2024 00:31:31.957247972 CEST1.1.1.1192.168.2.40xa24No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • cslseqirus.com.au
                    • https:
                      • www.cslseqirus.com.au
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44973512.3.33.229804144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Apr 19, 2024 00:30:21.784804106 CEST553OUTGET /products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html HTTP/1.1
                    Host: cslseqirus.com.au
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Accept-Encoding: gzip, deflate
                    Accept-Language: en-US,en;q=0.9
                    Apr 19, 2024 00:30:21.913495064 CEST255INHTTP/1.1 301 Moved permanently
                    Location: https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
                    Connection: close
                    Cache-Control: no-cache
                    Pragma: no-cache


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44973612.3.33.229804144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Apr 19, 2024 00:31:06.820270061 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44973712.3.33.229804144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    Apr 19, 2024 00:31:06.820349932 CEST6OUTData Raw: 00
                    Data Ascii:


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44974012.3.33.2294434144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 22:30:22 UTC781OUTGET /products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html HTTP/1.1
                    Host: cslseqirus.com.au
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 22:30:22 UTC418INHTTP/1.1 400 Bad Request
                    Cache-Control: private
                    Content-Type: text/html; charset=utf-8
                    Server: Microsoft-IIS/10.0
                    X-Frame-Options: SAMEORIGIN
                    CSL-Asset: PW102
                    Date: Thu, 18 Apr 2024 22:30:22 GMT
                    Connection: close
                    Content-Length: 3420
                    Strict-Transport-Security: max-age=157680000
                    Set-Cookie: NSC_JOra11xob1bq0rlcpeqchyc50zbpset=ffffffffaf1c1f1a45525d5f4f58455e445a4a42378b;Version=1;path=/;secure;httponly
                    2024-04-18 22:30:22 UTC3420INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 20 20 20 20 3c 68 65 61 64 3e 0d 0a 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 52 75 6e 74 69 6d 65 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 56 65 72 64 61 6e 61 22 3b 66 6f 6e 74 2d 77 65 69 67 68 74 3a 6e 6f 72 6d 61 6c 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 2e 37 65 6d 3b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 20 0d 0a 20 20 20 20 20 20 20 20 20 70 20 7b
                    Data Ascii: <!DOCTYPE html><html> <head> <title>Runtime Error</title> <meta name="viewport" content="width=device-width" /> <style> body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;} p {


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44974112.3.33.2294434144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 22:30:23 UTC801OUTGET /favicon.ico HTTP/1.1
                    Host: cslseqirus.com.au
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NSC_JOra11xob1bq0rlcpeqchyc50zbpset=ffffffffaf1c1f1a45525d5f4f58455e445a4a42378b
                    2024-04-18 22:30:23 UTC282INHTTP/1.1 301 Moved Permanently
                    Content-Type: text/html
                    Location: https://www.cslseqirus.com.au/favicon.ico
                    X-Frame-Options: SAMEORIGIN
                    CSL-Asset: PW102
                    Date: Thu, 18 Apr 2024 22:30:22 GMT
                    Connection: close
                    Content-Length: 251
                    Strict-Transport-Security: max-age=157680000
                    2024-04-18 22:30:23 UTC251INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 63 73 6c 73 65 71 69 72 75 73 2e 63 6f 6d 2e 61 75 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://www.cslseqirus.com.au/favicon.ico">here</a>.</p></body></html>


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44974223.44.104.130443
                    TimestampBytes transferredDirectionData
                    2024-04-18 22:30:24 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-18 22:30:24 UTC467INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/0758)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus-z1
                    Cache-Control: public, max-age=203633
                    Date: Thu, 18 Apr 2024 22:30:24 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.44974512.3.33.2294434144C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-18 22:30:24 UTC592OUTGET /favicon.ico HTTP/1.1
                    Host: www.cslseqirus.com.au
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-site
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://cslseqirus.com.au/
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-18 22:30:24 UTC330INHTTP/1.1 404 Not Found
                    Content-Type: text/html
                    X-Frame-Options: SAMEORIGIN
                    CSL-Asset: PW102
                    Date: Thu, 18 Apr 2024 22:30:24 GMT
                    Content-Length: 1245
                    Strict-Transport-Security: max-age=157680000
                    Set-Cookie: NSC_JOmrp15jeaeqsxwbccac2kct5r4yjbf=ffffffffaf1c1f1a45525d5f4f58455e445a4a42378b;Version=1;path=/;secure;httponly
                    2024-04-18 22:30:24 UTC1245INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c
                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/><title>404 - Fil


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.44974623.44.104.130443
                    TimestampBytes transferredDirectionData
                    2024-04-18 22:30:24 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-18 22:30:25 UTC531INHTTP/1.1 200 OK
                    Content-Type: application/octet-stream
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=203613
                    Date: Thu, 18 Apr 2024 22:30:25 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-04-18 22:30:25 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:00:30:15
                    Start date:19/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:00:30:18
                    Start date:19/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=2212,i,4724009423031868546,16661224601431264190,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:00:30:20
                    Start date:19/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cslseqirus.com.au/products%3Chttps://apneducationalmedia.writemsg.com/ch/69209/cpvp32/2239927/yojLwr1E3O_xOcBsCc.9_g7sRCMuRkontEXd8FjA.html"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly