Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png

Overview

General Information

Sample URL:https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png
Analysis ID:1428709
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1668 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2392 --field-trial-handle=2352,i,5685322909772573257,13647909739855469343,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6488 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.pngHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.208.128.100
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.26
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.26
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png HTTP/1.1Host: assets.smartlead.aiConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: assets.smartlead.aiConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.pngAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: assets.smartlead.ai
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeDate: Fri, 19 Apr 2024 10:45:50 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 d6a35bbafad9c6ab102b2f66ffd65942.cloudfront.net (CloudFront)X-Amz-Cf-Pop: ATL56-P1X-Amz-Cf-Id: SVAJ9P7tSBMSbbzwUoQ4-PFT6cL-UORbeA2cN58z35oevukbyj3aSg==
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.208.128.100:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2392 --field-trial-handle=2352,i,5685322909772573257,13647909739855469343,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2392 --field-trial-handle=2352,i,5685322909772573257,13647909739855469343,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    d1w75e4lle21p2.cloudfront.net
    18.64.236.123
    truefalse
      high
      www.google.com
      172.253.124.105
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          assets.smartlead.ai
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.pngfalse
              unknown
              https://assets.smartlead.ai/favicon.icofalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                18.64.236.123
                d1w75e4lle21p2.cloudfront.netUnited States
                3MIT-GATEWAYSUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                172.253.124.105
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1428709
                Start date and time:2024-04-19 12:44:51 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 18s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/4@4/4
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 173.194.219.94, 142.251.15.139, 142.251.15.102, 142.251.15.138, 142.251.15.101, 142.251.15.100, 142.251.15.113, 74.125.136.84, 34.104.35.123, 20.12.23.50, 199.232.210.172, 13.95.31.18, 192.229.211.108, 74.125.138.94
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, ASCII text
                Category:downloaded
                Size (bytes):255
                Entropy (8bit):5.644155687415402
                Encrypted:false
                SSDEEP:6:TMVBd/ZbZjZvKtWRVzjui/FKhjottgxzlWNSy95fgmXY/an:TMHd9BZKtWRnKhEtStynIsY/a
                MD5:7824088429D73A4C4E7CEB1E8DC9DE95
                SHA1:C13621D48B5712BC7244DCA1D7544FD3619C99C7
                SHA-256:FE8DF4FAE278D58035FE2D69A189BEB753765DB7EE46E4A2538F1958B7C59F2E
                SHA-512:CA7E01E572BEBE0F4968988D8F1767D3D1E632D51C570286DF83D6574A1AB6B5D9649CABC91DCA86BD032B1E623E8B8F7E2FBF9832742D5B28415F2F42183066
                Malicious:false
                Reputation:low
                URL:https://assets.smartlead.ai/favicon.ico
                Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>KWKCJNTGNM7YBZHT</RequestId><HostId>8GtNwM8NUNEEZdcocRrx02aHE2Z0NKm1T5m9Xt3eBwS7E954geazfwR0Vj+OJh3j66+qRtCAhjO76XoLMA/XFw==</HostId></Error>
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 126 x 126, 8-bit/color RGBA, non-interlaced
                Category:downloaded
                Size (bytes):3957
                Entropy (8bit):7.937466239616953
                Encrypted:false
                SSDEEP:96:o4trh/VrwsoEDi/82yhZXE/7ZmfKcgeqq4yle:o4z/Vrw182SZElmCTTUQ
                MD5:50D2BD530C3748FE4F5AB9833E45C6E7
                SHA1:DD5FA4EBF4662279740AC7390C3030301ADB3AC5
                SHA-256:DB06DE3B18FE432134F543B4A1D5CD4116445EB19AEBFB2BD037D25D51B8E272
                SHA-512:B0737DCFB548EEDD17DAC108081D21E29DD8C1C7329D4D4B7D42FAC2A38D49617351A888396EE024066E7D86E7B35FBCAE164EBDC4D2840F01D833485D298B45
                Malicious:false
                Reputation:low
                URL:https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png
                Preview:.PNG........IHDR...~...~......#......pHYs...........~....'IDATx..]...E..L...x......^....p..0...5...(!.+......#.*r(...( *.(........0......."../..MUM]]]MWU....._.....gVV...Z6""l.....Dt#............xI../)".%ED........""^RD.K.)...}..=.A...)HG<H_.."e...+.M....)...x&.u.\..S..B...x#..2./..V.3d#_..G.4.t..>u...+...9I.Z..!.[.9..%....-...x'..S......^...+..!>..3.H~h.w...E.B.(.....""^RD.K.)....G.H.YHG<H...>.$...x&}..| Mf!....Z..x'.p......_..h.B}...m.......,..~.=./..,. ...Z.2.}..{ ....x&.........i-.....L.n.#...@..7..A$?0...tF.....l...N...........e..(.7..g.t ...A.|_.....;....}K...B,#x.pABh...-...|_...d.^..O....|.............$.....o.?..38...A%.7.c...>..MIw.p.. .I..y..!~...m..{.(S.q.y..dzp..5.m.o...df.|.bw....._9wA#?.....9/.O'.L:.5.....B.I'?.l..&..t.. .W.;...r.a!..0,{..>;..D:.e.N...t...t./#.......0.J6.)......W..t........N:....T..3wF...@:.;1...D....$.....V...Wv..g.azx..y...L!...P.K..h.>.}k..]...@.O....K..`...$......S....t.lI.[X!<..O.pl.W...R(. ?.K..n../...9
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 19, 2024 12:45:39.802308083 CEST49675443192.168.2.4173.222.162.32
                Apr 19, 2024 12:45:49.426011086 CEST49675443192.168.2.4173.222.162.32
                Apr 19, 2024 12:45:50.053560972 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.053632021 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.054142952 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.054225922 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.054306030 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.054569006 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.054595947 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.054611921 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.054759026 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.054790974 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.284548998 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.284997940 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.285027027 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.286566019 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.286653996 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.286746025 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.288464069 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.288522005 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.289453983 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.289530039 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.289627075 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.289634943 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.290174007 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.290255070 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.291124105 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.291362047 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.332814932 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.428411007 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.428467035 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.481384993 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.537516117 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.537862062 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.537944078 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.537955999 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.538003922 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.538484097 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.538517952 CEST4434973518.64.236.123192.168.2.4
                Apr 19, 2024 12:45:50.538573027 CEST49735443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.589021921 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:50.636173964 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:51.520204067 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:51.520468950 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:51.520536900 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:51.549685955 CEST49736443192.168.2.418.64.236.123
                Apr 19, 2024 12:45:51.549726963 CEST4434973618.64.236.123192.168.2.4
                Apr 19, 2024 12:45:52.566850901 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.566932917 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.567167044 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.567871094 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.567909002 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.795532942 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.796030045 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.796087980 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.797676086 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.800246000 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.800246000 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.800357103 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.848058939 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:52.848117113 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:45:52.894927979 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:45:53.108486891 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.108530998 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.109404087 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.111877918 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.111896038 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.332828045 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.332926035 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.341237068 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.341255903 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.341917992 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.394809008 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.428896904 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.476165056 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.534388065 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.534456015 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.534516096 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.534575939 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.534575939 CEST49740443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.534611940 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.534641027 CEST4434974023.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.570952892 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.570990086 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.571065903 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.571329117 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.571343899 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.785526991 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.785617113 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.787169933 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.787180901 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.787501097 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.788646936 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.836113930 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.994044065 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.994231939 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:45:53.994321108 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.995563030 CEST49741443192.168.2.423.208.128.100
                Apr 19, 2024 12:45:53.995584011 CEST4434974123.208.128.100192.168.2.4
                Apr 19, 2024 12:46:02.831547022 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:02.831696987 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:02.831784010 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:03.517848969 CEST4972380192.168.2.4199.232.214.172
                Apr 19, 2024 12:46:03.622009993 CEST8049723199.232.214.172192.168.2.4
                Apr 19, 2024 12:46:03.622066021 CEST8049723199.232.214.172192.168.2.4
                Apr 19, 2024 12:46:03.622242928 CEST4972380192.168.2.4199.232.214.172
                Apr 19, 2024 12:46:04.696588993 CEST49739443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:04.696650982 CEST44349739172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.512063026 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:52.512166023 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.512254000 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:52.513010025 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:52.513051033 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.734500885 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.734930992 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:52.734977961 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.736076117 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.736547947 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:52.736728907 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:46:52.786120892 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:46:53.005413055 CEST4972480192.168.2.423.40.205.26
                Apr 19, 2024 12:46:53.109476089 CEST804972423.40.205.26192.168.2.4
                Apr 19, 2024 12:46:53.109620094 CEST4972480192.168.2.423.40.205.26
                Apr 19, 2024 12:47:02.741324902 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:47:02.741470098 CEST44349750172.253.124.105192.168.2.4
                Apr 19, 2024 12:47:02.742234945 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:47:05.004097939 CEST49750443192.168.2.4172.253.124.105
                Apr 19, 2024 12:47:05.004132986 CEST44349750172.253.124.105192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 19, 2024 12:45:48.269248962 CEST53523481.1.1.1192.168.2.4
                Apr 19, 2024 12:45:48.406269073 CEST53629941.1.1.1192.168.2.4
                Apr 19, 2024 12:45:49.014054060 CEST53554281.1.1.1192.168.2.4
                Apr 19, 2024 12:45:49.897294998 CEST5955753192.168.2.41.1.1.1
                Apr 19, 2024 12:45:49.897413969 CEST5998053192.168.2.41.1.1.1
                Apr 19, 2024 12:45:50.018126011 CEST53595571.1.1.1192.168.2.4
                Apr 19, 2024 12:45:50.112670898 CEST53599801.1.1.1192.168.2.4
                Apr 19, 2024 12:45:52.460267067 CEST5129253192.168.2.41.1.1.1
                Apr 19, 2024 12:45:52.460517883 CEST5801353192.168.2.41.1.1.1
                Apr 19, 2024 12:45:52.564871073 CEST53512921.1.1.1192.168.2.4
                Apr 19, 2024 12:45:52.564917088 CEST53580131.1.1.1192.168.2.4
                Apr 19, 2024 12:46:04.577646971 CEST138138192.168.2.4192.168.2.255
                Apr 19, 2024 12:46:06.329370975 CEST53495261.1.1.1192.168.2.4
                Apr 19, 2024 12:46:25.534656048 CEST53618581.1.1.1192.168.2.4
                Apr 19, 2024 12:46:48.239073038 CEST53551351.1.1.1192.168.2.4
                Apr 19, 2024 12:46:48.637675047 CEST53598731.1.1.1192.168.2.4
                TimestampSource IPDest IPChecksumCodeType
                Apr 19, 2024 12:45:50.112781048 CEST192.168.2.41.1.1.1c269(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 19, 2024 12:45:49.897294998 CEST192.168.2.41.1.1.10xf82eStandard query (0)assets.smartlead.aiA (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:49.897413969 CEST192.168.2.41.1.1.10x4902Standard query (0)assets.smartlead.ai65IN (0x0001)false
                Apr 19, 2024 12:45:52.460267067 CEST192.168.2.41.1.1.10xa837Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.460517883 CEST192.168.2.41.1.1.10x328Standard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 19, 2024 12:45:50.018126011 CEST1.1.1.1192.168.2.40xf82eNo error (0)assets.smartlead.aid1w75e4lle21p2.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:45:50.018126011 CEST1.1.1.1192.168.2.40xf82eNo error (0)d1w75e4lle21p2.cloudfront.net18.64.236.123A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:50.018126011 CEST1.1.1.1192.168.2.40xf82eNo error (0)d1w75e4lle21p2.cloudfront.net18.64.236.87A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:50.018126011 CEST1.1.1.1192.168.2.40xf82eNo error (0)d1w75e4lle21p2.cloudfront.net18.64.236.94A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:50.018126011 CEST1.1.1.1192.168.2.40xf82eNo error (0)d1w75e4lle21p2.cloudfront.net18.64.236.104A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:50.112670898 CEST1.1.1.1192.168.2.40x4902No error (0)assets.smartlead.aid1w75e4lle21p2.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.105A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.104A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.99A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.103A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.106A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564871073 CEST1.1.1.1192.168.2.40xa837No error (0)www.google.com172.253.124.147A (IP address)IN (0x0001)false
                Apr 19, 2024 12:45:52.564917088 CEST1.1.1.1192.168.2.40x328No error (0)www.google.com65IN (0x0001)false
                Apr 19, 2024 12:46:03.184953928 CEST1.1.1.1192.168.2.40x93f4No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 19, 2024 12:46:03.184953928 CEST1.1.1.1192.168.2.40x93f4No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 19, 2024 12:46:04.249974966 CEST1.1.1.1192.168.2.40x95c0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:46:04.249974966 CEST1.1.1.1192.168.2.40x95c0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 12:46:21.450256109 CEST1.1.1.1192.168.2.40x7135No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:46:21.450256109 CEST1.1.1.1192.168.2.40x7135No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 12:46:40.658159971 CEST1.1.1.1192.168.2.40xa006No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:46:40.658159971 CEST1.1.1.1192.168.2.40xa006No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 19, 2024 12:47:01.024811029 CEST1.1.1.1192.168.2.40xe2cfNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 19, 2024 12:47:01.024811029 CEST1.1.1.1192.168.2.40xe2cfNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • assets.smartlead.ai
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44973518.64.236.1234431668C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-19 10:45:50 UTC742OUTGET /user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png HTTP/1.1
                Host: assets.smartlead.ai
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-19 10:45:50 UTC519INHTTP/1.1 200 OK
                Content-Type: image/png
                Content-Length: 3957
                Connection: close
                Last-Modified: Thu, 04 Apr 2024 10:09:25 GMT
                x-amz-server-side-encryption: AES256
                Accept-Ranges: bytes
                Server: AmazonS3
                Date: Thu, 18 Apr 2024 19:53:25 GMT
                ETag: "50d2bd530c3748fe4f5ab9833e45c6e7"
                Vary: Accept-Encoding
                X-Cache: Hit from cloudfront
                Via: 1.1 8c7b20060d90bea31f16760f6840aa40.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: ATL56-P1
                X-Amz-Cf-Id: KBD7nz3m0JrRxRThq9Is5K3wbHP7KI8xSiOfts9NLmENa5DDiQtKDg==
                Age: 53546
                2024-04-19 10:45:50 UTC3957INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 7e 00 00 00 7e 08 06 00 00 00 e2 23 a5 88 00 00 00 09 70 48 59 73 00 00 0b 12 00 00 0b 12 01 d2 dd 7e fc 00 00 0f 27 49 44 41 54 78 9c ed 5d 09 90 14 45 16 fd 4c 83 e8 aa 03 78 e0 01 0c b7 83 1c 5e bb c2 82 a0 c8 70 a8 a8 30 01 03 c8 35 02 ba 0a 28 21 88 2b 88 ac c0 a8 80 b7 23 08 2a 72 28 a2 80 08 28 20 2a 84 28 03 86 10 ba c8 a5 86 ae ae 30 0c ab bb ab cc 18 ab 22 82 1b 2f bb 7f 4d 55 4d 5d 5d 5d 4d 57 55 d6 8b a8 e8 ae ee ac cc 5f f5 f2 ff fa ff 67 56 56 b5 da f5 5a 36 22 22 6c 11 e4 c1 a1 ea 44 74 23 11 dd 17 91 2e 15 de cb 92 fd 0a c8 8a 88 78 49 11 11 2f 29 22 e2 25 45 44 bc a4 88 88 97 14 11 f1 92 22 22 5e 52 44 c4 4b 0a 29 89 af 95 7d aa f2 3d a7 41 bd 8c ca 92 29 48 47 3c 48 5f f3 ea 22 65
                Data Ascii: PNGIHDR~~#pHYs~'IDATx]ELx^p05(!+#*r(( *(0"/MUM]]]MWU_gVVZ6""lDt#.xI/)"%ED""^RDK)}=A)HG<H_"e


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44973618.64.236.1234431668C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-19 10:45:50 UTC674OUTGET /favicon.ico HTTP/1.1
                Host: assets.smartlead.ai
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-19 10:45:51 UTC357INHTTP/1.1 403 Forbidden
                Content-Type: application/xml
                Transfer-Encoding: chunked
                Connection: close
                Date: Fri, 19 Apr 2024 10:45:50 GMT
                Server: AmazonS3
                X-Cache: Error from cloudfront
                Via: 1.1 d6a35bbafad9c6ab102b2f66ffd65942.cloudfront.net (CloudFront)
                X-Amz-Cf-Pop: ATL56-P1
                X-Amz-Cf-Id: SVAJ9P7tSBMSbbzwUoQ4-PFT6cL-UORbeA2cN58z35oevukbyj3aSg==
                2024-04-19 10:45:51 UTC261INData Raw: 66 66 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 44 65 6e 69 65 64 3c 2f 4d 65 73 73 61 67 65 3e 3c 52 65 71 75 65 73 74 49 64 3e 4b 57 4b 43 4a 4e 54 47 4e 4d 37 59 42 5a 48 54 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 38 47 74 4e 77 4d 38 4e 55 4e 45 45 5a 64 63 6f 63 52 72 78 30 32 61 48 45 32 5a 30 4e 4b 6d 31 54 35 6d 39 58 74 33 65 42 77 53 37 45 39 35 34 67 65 61 7a 66 77 52 30 56 6a 2b 4f 4a 68 33 6a 36 36 2b 71 52 74 43 41 68 6a 4f 37 36 58 6f 4c 4d 41 2f 58 46 77 3d 3d 3c 2f 48 6f 73 74 49 64 3e 3c 2f 45 72
                Data Ascii: ff<?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>KWKCJNTGNM7YBZHT</RequestId><HostId>8GtNwM8NUNEEZdcocRrx02aHE2Z0NKm1T5m9Xt3eBwS7E954geazfwR0Vj+OJh3j66+qRtCAhjO76XoLMA/XFw==</HostId></Er
                2024-04-19 10:45:51 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44974023.208.128.100443
                TimestampBytes transferredDirectionData
                2024-04-19 10:45:53 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-19 10:45:53 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (chd/073D)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=159492
                Date: Fri, 19 Apr 2024 10:45:53 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974123.208.128.100443
                TimestampBytes transferredDirectionData
                2024-04-19 10:45:53 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-19 10:45:53 UTC531INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                Cache-Control: public, max-age=159356
                Date: Fri, 19 Apr 2024 10:45:53 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-19 10:45:53 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:12:45:43
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:12:45:46
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2392 --field-trial-handle=2352,i,5685322909772573257,13647909739855469343,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:12:45:49
                Start date:19/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://assets.smartlead.ai/user/8424/cdffff31-8bfd-4867-b0e2-cb008211677d/1000_x_1000_f___Wayne_Capital.png"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly