Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==

Overview

General Information

Sample URL:https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==
Analysis ID:1428648
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4960 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5984 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1868,i,3700358645636935463,13062378885552609006,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 23.55.253.34
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /cb/ HTTP/1.1Host: signsandlighting.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /configurations.aspx?look=dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ== HTTP/1.1Host: email.authourities.shopConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://signsandlighting.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: signsandlighting.com
Source: unknownHTTP traffic detected: POST /report/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 496Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 19 Apr 2024 09:07:40 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeExpires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidatePragma: no-cacheSet-Cookie: PHPSESSID=7o7don9gsgi0o7l9ti5vaj65dt; path=/CF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 876bbede787c44db-ATLalt-svc: h3=":443"; ma=86400
Source: chromecache_41.2.drString found in binary or memory: https://email.authourities.shop/configurations.aspx?look=
Source: chromecache_41.2.drString found in binary or memory: https://www.cnn.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.55.253.34:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: classification engineClassification label: clean0.win@18/2@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1868,i,3700358645636935463,13062378885552609006,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ=="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1868,i,3700358645636935463,13062378885552609006,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==3%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://email.authourities.shop/configurations.aspx?look=0%VirustotalBrowse
https://signsandlighting.com/cb/3%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
signsandlighting.com
67.20.76.95
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      email.authourities.shop
      172.67.183.55
      truefalse
        unknown
        www.google.com
        64.233.176.147
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://signsandlighting.com/cb/falseunknown
            https://a.nel.cloudflare.com/report/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3Dfalse
              high
              https://email.authourities.shop/configurations.aspx?look=dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==false
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.cnn.comchromecache_41.2.drfalse
                  high
                  https://email.authourities.shop/configurations.aspx?look=chromecache_41.2.drfalseunknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  172.67.183.55
                  email.authourities.shopUnited States
                  13335CLOUDFLARENETUSfalse
                  35.190.80.1
                  a.nel.cloudflare.comUnited States
                  15169GOOGLEUSfalse
                  64.233.176.147
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  67.20.76.95
                  signsandlighting.comUnited States
                  46606UNIFIEDLAYER-AS-1USfalse
                  IP
                  192.168.2.4
                  Joe Sandbox version:40.0.0 Tourmaline
                  Analysis ID:1428648
                  Start date and time:2024-04-19 11:06:45 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 3m 10s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ==
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@18/2@8/6
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 74.125.138.94, 64.233.176.139, 64.233.176.102, 64.233.176.100, 64.233.176.101, 64.233.176.138, 64.233.176.113, 142.250.105.84, 34.104.35.123, 13.85.23.86, 23.40.205.34, 23.40.205.26, 192.229.211.108, 52.165.164.15, 20.242.39.171, 142.250.9.94
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with CRLF line terminators
                  Category:downloaded
                  Size (bytes):781
                  Entropy (8bit):4.337051657350569
                  Encrypted:false
                  SSDEEP:12:hPEaccfcDDawrpGSCrSt+PtWihfjAvm0nc0YvxHfOFCxgujDDexHTK3XDqMWMGb:hPtTUDDaQ+VWihku0ngRbJDqMzM
                  MD5:FC29627DD34F9EEF440D0D1CB36EB36E
                  SHA1:BE8C0462EF9584BAB8CE614806A668CEA22EDBC8
                  SHA-256:B058DF959128F1A0666AB0304F5C1D791DE223260C5D643829F943CAED3D1FDB
                  SHA-512:3191304B08D06A291AD848CA67096FEEBAE821CA275A1A9A0CC32875C742BF274B54A22E687A9F192CF2B78E4256A9BA0C49E3C772C968AB53F91BF83F473C8D
                  Malicious:false
                  Reputation:low
                  URL:https://signsandlighting.com/cb/
                  Preview:<!DOCTYPE html>..<html>....<head>..</head>....<body>.... <script>.. function redirrectPage() {.. var query = window.location.href;.. console.log(query);.. var res = query.split("#");.. var data1 = res[0];.. var data2 = res[1];.. console.log(data1);.. console.log(data2);.... //data2 = atob(data2);.... if (data2) {.. console.log("true");.. window.location.href = "https://email.authourities.shop/configurations.aspx?look=" + data2;.. } else {.. console.log("false");.. window.location.href = "https://www.cnn.com";.. }.. }.. redirrectPage();.. </script>..</body>....</html>
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 19, 2024 11:07:28.650572062 CEST49678443192.168.2.4104.46.162.224
                  Apr 19, 2024 11:07:30.200964928 CEST49675443192.168.2.4173.222.162.32
                  Apr 19, 2024 11:07:38.703917027 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.703963995 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:38.704041004 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.704472065 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.704511881 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:38.704655886 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.704675913 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:38.704679012 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.704910040 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:38.704921961 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.023453951 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.023781061 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.023834944 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.026099920 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.026180983 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.027236938 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.027337074 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.027443886 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.027466059 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.029158115 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.029376030 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.029409885 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.030841112 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.030893087 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.031676054 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.031758070 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.072679043 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.072684050 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.072742939 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.125808001 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.331600904 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.331837893 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.332936049 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.333142996 CEST49736443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:39.333182096 CEST4434973667.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:39.497327089 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.497364044 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.497425079 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.497956991 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.498059034 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.498131990 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.498230934 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.498244047 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.498409986 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.498447895 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.715713024 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.716042042 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.716104031 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.717005014 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.717087030 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.717787981 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.718015909 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.718043089 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.718135118 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.718205929 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.718312025 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.718329906 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.721803904 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.721873999 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.722124100 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.722295046 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.757890940 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.773082972 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:39.773107052 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:39.803510904 CEST49675443192.168.2.4173.222.162.32
                  Apr 19, 2024 11:07:39.818717003 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:40.856986046 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:40.857053041 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:40.857103109 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:40.859597921 CEST49740443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:40.859625101 CEST44349740172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:40.999809027 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:40.999859095 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:40.999914885 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.000185966 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.000196934 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.214498043 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.220172882 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.220236063 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.221330881 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.221425056 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.225533009 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.225657940 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.226046085 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.226063967 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.275677919 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.442851067 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.442917109 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.442965031 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.443140030 CEST49741443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.443159103 CEST4434974135.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.443676949 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.443763018 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.443825960 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.444073915 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.444097042 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.656824112 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.657162905 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.657185078 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.657685041 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.658010006 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.658147097 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.658153057 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.658237934 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.704560995 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.728224993 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:41.728266954 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:41.728560925 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:41.730710030 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:41.730739117 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:41.889460087 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.889544010 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:41.889810085 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.889810085 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:41.950519085 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:41.950815916 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:41.956490040 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:41.956568956 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:41.956680059 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:41.956693888 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:41.956831932 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:41.957088947 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:41.957134962 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:41.957170963 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.008449078 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.029108047 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.076114893 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.146655083 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.146753073 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.146881104 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.156014919 CEST49743443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.156037092 CEST4434974323.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.173549891 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.174459934 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:42.174519062 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.175951958 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.176172972 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:42.180907965 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:42.181072950 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.196918011 CEST49742443192.168.2.435.190.80.1
                  Apr 19, 2024 11:07:42.196986914 CEST4434974235.190.80.1192.168.2.4
                  Apr 19, 2024 11:07:42.204916954 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.205007076 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.205179930 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.207829952 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.207865000 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.228907108 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:42.228931904 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:42.276904106 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:42.423022032 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.423228979 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.424685955 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.424725056 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.425132036 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.430327892 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.476121902 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.624870062 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.625039101 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.629034996 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.634568930 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.634613037 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:42.634656906 CEST49745443192.168.2.423.55.253.34
                  Apr 19, 2024 11:07:42.634671926 CEST4434974523.55.253.34192.168.2.4
                  Apr 19, 2024 11:07:49.184295893 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:49.184506893 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:49.184753895 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:49.389094114 CEST49735443192.168.2.467.20.76.95
                  Apr 19, 2024 11:07:49.389163971 CEST4434973567.20.76.95192.168.2.4
                  Apr 19, 2024 11:07:50.901267052 CEST49672443192.168.2.4173.222.162.32
                  Apr 19, 2024 11:07:50.901310921 CEST44349672173.222.162.32192.168.2.4
                  Apr 19, 2024 11:07:50.901621103 CEST49672443192.168.2.4173.222.162.32
                  Apr 19, 2024 11:07:50.901632071 CEST44349672173.222.162.32192.168.2.4
                  Apr 19, 2024 11:07:52.223735094 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:52.223902941 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:52.223970890 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:53.387079954 CEST49744443192.168.2.464.233.176.147
                  Apr 19, 2024 11:07:53.387141943 CEST4434974464.233.176.147192.168.2.4
                  Apr 19, 2024 11:07:54.705920935 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:54.706095934 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:07:54.706163883 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:55.057147026 CEST49739443192.168.2.4172.67.183.55
                  Apr 19, 2024 11:07:55.057188988 CEST44349739172.67.183.55192.168.2.4
                  Apr 19, 2024 11:08:41.892610073 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:41.892689943 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:41.893100023 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:41.895792961 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:41.895827055 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:42.111836910 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:42.112149954 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:42.112179041 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:42.112649918 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:42.113022089 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:42.113121033 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:42.165355921 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:47.618855953 CEST4972380192.168.2.4199.232.210.172
                  Apr 19, 2024 11:08:47.619077921 CEST4972480192.168.2.4199.232.210.172
                  Apr 19, 2024 11:08:47.720861912 CEST8049723199.232.210.172192.168.2.4
                  Apr 19, 2024 11:08:47.720885992 CEST8049723199.232.210.172192.168.2.4
                  Apr 19, 2024 11:08:47.720937967 CEST4972380192.168.2.4199.232.210.172
                  Apr 19, 2024 11:08:47.721040010 CEST8049724199.232.210.172192.168.2.4
                  Apr 19, 2024 11:08:47.721062899 CEST8049724199.232.210.172192.168.2.4
                  Apr 19, 2024 11:08:47.721106052 CEST4972480192.168.2.4199.232.210.172
                  Apr 19, 2024 11:08:52.121922016 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:52.122066021 CEST4434975464.233.176.147192.168.2.4
                  Apr 19, 2024 11:08:52.122160912 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:53.385920048 CEST49754443192.168.2.464.233.176.147
                  Apr 19, 2024 11:08:53.385957003 CEST4434975464.233.176.147192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 19, 2024 11:07:37.307060957 CEST53512411.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:37.323601007 CEST53531771.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:37.906186104 CEST53612981.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:38.562761068 CEST5856253192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:38.563344955 CEST5234353192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:38.700979948 CEST53523431.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:38.703145027 CEST53585621.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:39.360668898 CEST5439753192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:39.360927105 CEST5286653192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:39.493947983 CEST53528661.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:39.495965004 CEST53543971.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:40.865844965 CEST5253953192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:40.867245913 CEST6239953192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:40.974409103 CEST53525391.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:40.975898027 CEST53623991.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:41.848217010 CEST5219153192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:41.848901033 CEST6361253192.168.2.41.1.1.1
                  Apr 19, 2024 11:07:41.951085091 CEST53521911.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:41.951889038 CEST53636121.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:55.161050081 CEST53519171.1.1.1192.168.2.4
                  Apr 19, 2024 11:07:59.170605898 CEST138138192.168.2.4192.168.2.255
                  Apr 19, 2024 11:08:14.436897039 CEST53510051.1.1.1192.168.2.4
                  Apr 19, 2024 11:08:36.804013014 CEST53597231.1.1.1192.168.2.4
                  Apr 19, 2024 11:08:36.880477905 CEST53499761.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Apr 19, 2024 11:07:38.562761068 CEST192.168.2.41.1.1.10xc717Standard query (0)signsandlighting.comA (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:38.563344955 CEST192.168.2.41.1.1.10x60e9Standard query (0)signsandlighting.com65IN (0x0001)false
                  Apr 19, 2024 11:07:39.360668898 CEST192.168.2.41.1.1.10xc7faStandard query (0)email.authourities.shopA (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:39.360927105 CEST192.168.2.41.1.1.10x24d5Standard query (0)email.authourities.shop65IN (0x0001)false
                  Apr 19, 2024 11:07:40.865844965 CEST192.168.2.41.1.1.10x51a9Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:40.867245913 CEST192.168.2.41.1.1.10x2500Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                  Apr 19, 2024 11:07:41.848217010 CEST192.168.2.41.1.1.10xf6f9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.848901033 CEST192.168.2.41.1.1.10xebfcStandard query (0)www.google.com65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Apr 19, 2024 11:07:38.703145027 CEST1.1.1.1192.168.2.40xc717No error (0)signsandlighting.com67.20.76.95A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:39.493947983 CEST1.1.1.1192.168.2.40x24d5No error (0)email.authourities.shop65IN (0x0001)false
                  Apr 19, 2024 11:07:39.495965004 CEST1.1.1.1192.168.2.40xc7faNo error (0)email.authourities.shop172.67.183.55A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:39.495965004 CEST1.1.1.1192.168.2.40xc7faNo error (0)email.authourities.shop104.21.51.176A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:40.974409103 CEST1.1.1.1192.168.2.40x51a9No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.147A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.106A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.104A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.105A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.99A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951085091 CEST1.1.1.1192.168.2.40xf6f9No error (0)www.google.com64.233.176.103A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:07:41.951889038 CEST1.1.1.1192.168.2.40xebfcNo error (0)www.google.com65IN (0x0001)false
                  Apr 19, 2024 11:07:53.224126101 CEST1.1.1.1192.168.2.40xebbcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 19, 2024 11:07:53.224126101 CEST1.1.1.1192.168.2.40xebbcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:08:06.362546921 CEST1.1.1.1192.168.2.40x62fdNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 19, 2024 11:08:06.362546921 CEST1.1.1.1192.168.2.40x62fdNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:08:29.522157907 CEST1.1.1.1192.168.2.40xb350No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 19, 2024 11:08:29.522157907 CEST1.1.1.1192.168.2.40xb350No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  Apr 19, 2024 11:08:49.693615913 CEST1.1.1.1192.168.2.40xfa85No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                  Apr 19, 2024 11:08:49.693615913 CEST1.1.1.1192.168.2.40xfa85No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                  • signsandlighting.com
                  • https:
                    • email.authourities.shop
                  • a.nel.cloudflare.com
                  • fs.microsoft.com
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.44973667.20.76.954435984C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:39 UTC666OUTGET /cb/ HTTP/1.1
                  Host: signsandlighting.com
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-19 09:07:39 UTC254INHTTP/1.1 200 OK
                  Date: Fri, 19 Apr 2024 09:07:39 GMT
                  Server: Apache
                  Upgrade: h2,h2c
                  Connection: Upgrade, close
                  Last-Modified: Mon, 15 Apr 2024 03:04:47 GMT
                  Accept-Ranges: bytes
                  Content-Length: 781
                  Vary: Accept-Encoding
                  Content-Type: text/html
                  2024-04-19 09:07:39 UTC781INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 0d 0a 3c 62 6f 64 79 3e 0d 0a 0d 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 0d 0a 20 20 20 20 20 20 20 20 66 75 6e 63 74 69 6f 6e 20 72 65 64 69 72 72 65 63 74 50 61 67 65 28 29 20 7b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 76 61 72 20 71 75 65 72 79 20 3d 20 77 69 6e 64 6f 77 2e 6c 6f 63 61 74 69 6f 6e 2e 68 72 65 66 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6e 73 6f 6c 65 2e 6c 6f 67 28 71 75 65 72 79 29 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 76 61 72 20 72 65 73 20 3d 20 71 75 65 72 79 2e 73 70 6c 69 74 28 22 23 22 29 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 76 61 72 20 64 61 74 61 31 20 3d 20 72 65 73 5b
                  Data Ascii: <!DOCTYPE html><html><head></head><body> <script> function redirrectPage() { var query = window.location.href; console.log(query); var res = query.split("#"); var data1 = res[


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.449740172.67.183.554435984C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:39 UTC765OUTGET /configurations.aspx?look=dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ== HTTP/1.1
                  Host: email.authourities.shop
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: cross-site
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-Dest: document
                  Referer: https://signsandlighting.com/
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-19 09:07:40 UTC763INHTTP/1.1 404 Not Found
                  Date: Fri, 19 Apr 2024 09:07:40 GMT
                  Content-Type: text/html; charset=UTF-8
                  Transfer-Encoding: chunked
                  Connection: close
                  Expires: Thu, 19 Nov 1981 08:52:00 GMT
                  Cache-Control: no-store, no-cache, must-revalidate
                  Pragma: no-cache
                  Set-Cookie: PHPSESSID=7o7don9gsgi0o7l9ti5vaj65dt; path=/
                  CF-Cache-Status: DYNAMIC
                  Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3D"}],"group":"cf-nel","max_age":604800}
                  NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                  Server: cloudflare
                  CF-RAY: 876bbede787c44db-ATL
                  alt-svc: h3=":443"; ma=86400
                  2024-04-19 09:07:40 UTC5INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.44974135.190.80.14435984C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:41 UTC558OUTOPTIONS /report/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3D HTTP/1.1
                  Host: a.nel.cloudflare.com
                  Connection: keep-alive
                  Origin: https://email.authourities.shop
                  Access-Control-Request-Method: POST
                  Access-Control-Request-Headers: content-type
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-19 09:07:41 UTC336INHTTP/1.1 200 OK
                  Content-Length: 0
                  access-control-max-age: 86400
                  access-control-allow-methods: OPTIONS, POST
                  access-control-allow-origin: *
                  access-control-allow-headers: content-type, content-length
                  date: Fri, 19 Apr 2024 09:07:41 GMT
                  Via: 1.1 google
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Connection: close


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.44974235.190.80.14435984C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:41 UTC492OUTPOST /report/v4?s=Jzkk8A58%2F4FgpE6huFbrilaeHF8BzBUODlLr52OPIRK6H%2B4pkgbInFj6B31mNEcCTqdimy2FNLB9dze4m58mZYHgIq8MFQuSCrdIs5FjWqa8yvuv9EIiQEuCKpRo8JnhEXwQn8SFn7S%2FeA%3D%3D HTTP/1.1
                  Host: a.nel.cloudflare.com
                  Connection: keep-alive
                  Content-Length: 496
                  Content-Type: application/reports+json
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-04-19 09:07:41 UTC496OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 34 39 31 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 73 69 67 6e 73 61 6e 64 6c 69 67 68 74 69 6e 67 2e 63 6f 6d 2f 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 38 33 2e 35 35 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22
                  Data Ascii: [{"age":5,"body":{"elapsed_time":1491,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://signsandlighting.com/","sampling_fraction":1.0,"server_ip":"172.67.183.55","status_code":404,"type":"http.error"},"type":"network-error","
                  2024-04-19 09:07:41 UTC168INHTTP/1.1 200 OK
                  Content-Length: 0
                  date: Fri, 19 Apr 2024 09:07:41 GMT
                  Via: 1.1 google
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Connection: close


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.44974323.55.253.34443
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:42 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-04-19 09:07:42 UTC467INHTTP/1.1 200 OK
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  Content-Type: application/octet-stream
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  Server: ECAcc (chd/0758)
                  X-CID: 11
                  X-Ms-ApiVersion: Distribute 1.2
                  X-Ms-Region: prod-eus-z1
                  Cache-Control: public, max-age=165354
                  Date: Fri, 19 Apr 2024 09:07:42 GMT
                  Connection: close
                  X-CID: 2


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  5192.168.2.44974523.55.253.34443
                  TimestampBytes transferredDirectionData
                  2024-04-19 09:07:42 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                  Connection: Keep-Alive
                  Accept: */*
                  Accept-Encoding: identity
                  If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                  Range: bytes=0-2147483646
                  User-Agent: Microsoft BITS/7.8
                  Host: fs.microsoft.com
                  2024-04-19 09:07:42 UTC531INHTTP/1.1 200 OK
                  Content-Type: application/octet-stream
                  Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                  ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                  ApiVersion: Distribute 1.1
                  Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                  X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                  Cache-Control: public, max-age=165289
                  Date: Fri, 19 Apr 2024 09:07:42 GMT
                  Content-Length: 55
                  Connection: close
                  X-CID: 2
                  2024-04-19 09:07:42 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                  Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:11:07:33
                  Start date:19/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:11:07:35
                  Start date:19/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1868,i,3700358645636935463,13062378885552609006,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:11:07:38
                  Start date:19/04/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://signsandlighting.com/cb/#dmFuZXNzYS5jaWV0ZXJzQGRhaWljaGktc2Fua3lvLmJlDQ=="
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  No disassembly