Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://ultra.ally.staging.riverus.io/

Overview

General Information

Sample URL:https://ultra.ally.staging.riverus.io/
Analysis ID:1428819
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2196 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 888 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2236 --field-trial-handle=2200,i,10461123817870828047,4255301424661301404,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ultra.ally.staging.riverus.io/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.197.2.6:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.197.2.6:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 23.197.2.6
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.11
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.205.11
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: ultra.ally.staging.riverus.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ultra.ally.staging.riverus.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ultra.ally.staging.riverus.io/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: ultra.ally.staging.riverus.io
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: application/xmlTransfer-Encoding: chunkedConnection: closeDate: Fri, 19 Apr 2024 15:01:31 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 7eeed291abf48890d3f36565208941a8.cloudfront.net (CloudFront)X-Amz-Cf-Pop: IAD12-P1X-Amz-Cf-Id: kbDN7CbJ6JgzT3-FLVkkQA3TA_r9vRmnc1S5hzQg4TUoruYU8NfZgw==
Source: chromecache_42.2.drString found in binary or memory: https://auth.riverus.io
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/assets/icon-16.png
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/assets/icon-32.png
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/assets/icon-80.png
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/assets/riverus-short-logo.png
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/commands.html
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/index.html
Source: chromecache_42.2.drString found in binary or memory: https://ultra.ally.staging.riverus.io/taskpane.html
Source: chromecache_42.2.drString found in binary or memory: https://www.riverus.in/help
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.197.2.6:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.197.2.6:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2236 --field-trial-handle=2200,i,10461123817870828047,4255301424661301404,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ultra.ally.staging.riverus.io/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2236 --field-trial-handle=2200,i,10461123817870828047,4255301424661301404,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    172.253.124.147
    truefalse
      high
      d15cg09v7rb8cb.cloudfront.net
      108.138.64.65
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          ultra.ally.staging.riverus.io
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://ultra.ally.staging.riverus.io/false
              unknown
              https://ultra.ally.staging.riverus.io/favicon.icofalse
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                https://auth.riverus.iochromecache_42.2.drfalse
                  unknown
                  https://ultra.ally.staging.riverus.iochromecache_42.2.drfalse
                    unknown
                    https://ultra.ally.staging.riverus.io/assets/icon-16.pngchromecache_42.2.drfalse
                      unknown
                      https://ultra.ally.staging.riverus.io/commands.htmlchromecache_42.2.drfalse
                        unknown
                        https://ultra.ally.staging.riverus.io/assets/icon-32.pngchromecache_42.2.drfalse
                          unknown
                          https://www.riverus.in/helpchromecache_42.2.drfalse
                            unknown
                            https://ultra.ally.staging.riverus.io/taskpane.htmlchromecache_42.2.drfalse
                              unknown
                              https://ultra.ally.staging.riverus.io/assets/icon-80.pngchromecache_42.2.drfalse
                                unknown
                                https://ultra.ally.staging.riverus.io/assets/riverus-short-logo.pngchromecache_42.2.drfalse
                                  unknown
                                  https://ultra.ally.staging.riverus.io/index.htmlchromecache_42.2.drfalse
                                    unknown
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    239.255.255.250
                                    unknownReserved
                                    unknownunknownfalse
                                    108.138.64.65
                                    d15cg09v7rb8cb.cloudfront.netUnited States
                                    16509AMAZON-02USfalse
                                    172.253.124.147
                                    www.google.comUnited States
                                    15169GOOGLEUSfalse
                                    IP
                                    192.168.2.4
                                    Joe Sandbox version:40.0.0 Tourmaline
                                    Analysis ID:1428819
                                    Start date and time:2024-04-19 17:00:32 +02:00
                                    Joe Sandbox product:CloudBasic
                                    Overall analysis duration:0h 3m 18s
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:browseurl.jbs
                                    Sample URL:https://ultra.ally.staging.riverus.io/
                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                    Number of analysed new started processes analysed:9
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:CLEAN
                                    Classification:clean0.win@16/4@4/4
                                    EGA Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                    • Excluded IPs from analysis (whitelisted): 64.233.185.94, 142.251.15.102, 142.251.15.113, 142.251.15.138, 142.251.15.139, 142.251.15.100, 142.251.15.101, 142.250.105.84, 34.104.35.123, 20.12.23.50, 199.232.210.172, 192.229.211.108, 20.3.187.198, 13.85.23.206
                                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtSetInformationFile calls found.
                                    • VT rate limit hit for: https://ultra.ally.staging.riverus.io/
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:downloaded
                                    Size (bytes):282
                                    Entropy (8bit):5.593743488101793
                                    Encrypted:false
                                    SSDEEP:6:TMVBd/ZbZj7lHcLWtpTQgRdWl5JLMPKU0/ChlYu4LejSMp9an:TMHd9BBHcLWIUUX5U0KozwSaa
                                    MD5:B2255DB9E10371397DFE087F298237FB
                                    SHA1:3EDA03EE16221894A7A224DE76F454849B7C071A
                                    SHA-256:4BACCE79DF292AA9AFC1A554C58E92B50DAC0A9CB7C0B9064528215D85AF7C61
                                    SHA-512:08C5E565DA650DEB716B6F749A903859AADCF23EAD372F5EE81E806D11BEA7A7813DE606295CDF98756F9F65D5A7B43DBC4205CE109901D63099707ED9BBBC78
                                    Malicious:false
                                    Reputation:low
                                    URL:https://ultra.ally.staging.riverus.io/favicon.ico
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>.<Error><Code>NoSuchKey</Code><Message>The specified key does not exist.</Message><Key>favicon.ico</Key><RequestId>J71R5227SHNPPKZA</RequestId><HostId>lG87aUzf/JdYO+dSrJwFWbeSSWLQ/FNvS3FMRbH5gcXYRi0hlGrWREKcorAWBQ8m5riDZid0/i0=</HostId></Error>
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:downloaded
                                    Size (bytes):4325
                                    Entropy (8bit):4.891004561671322
                                    Encrypted:false
                                    SSDEEP:48:c8Ax81yLIIXU6tSJ1lm8zt82LFvGSf0out9D/C4u0O6FmbePNG0ZiCF:tAMyfk1u8ztFNXqTC4u0O6FCk
                                    MD5:B11C60AD7DB09C6DBDC8B9BA7BEC8681
                                    SHA1:BCDCF377E8453BAF5AF3EF82DA117ADC5E5ED86B
                                    SHA-256:45114E580542D5F980A9A8B847D9C84C29C5200D14CA1BB6EBBC3670FE0096F1
                                    SHA-512:143D6CAF355770BE010DDCA9352AC5F466C8433C5E1228918DFE230EEEC1E0BAF4B6B72301E26C259CC3C6B740C5B2A9306C42CCE2B6C74536F8C669ED8F583B
                                    Malicious:false
                                    Reputation:low
                                    URL:https://ultra.ally.staging.riverus.io/
                                    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.<OfficeApp xmlns="http://schemas.microsoft.com/office/appforoffice/1.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:bt="http://schemas.microsoft.com/office/officeappbasictypes/1.0" xmlns:ov="http://schemas.microsoft.com/office/taskpaneappversionoverrides" xsi:type="TaskPaneApp">. <Id>4ac1823b-d34f-4331-b0c9-4016e55287f1</Id>. <Version>1.0.14.0</Version>. <ProviderName>Riverus Technology Solutions Pvt Ltd</ProviderName>. <DefaultLocale>en-US</DefaultLocale>. <DisplayName DefaultValue="Ultra Ally (staging)"/>. <Description DefaultValue="ULTRA Ally is word add-in"/>. <IconUrl DefaultValue="https://ultra.ally.staging.riverus.io/assets/riverus-short-logo.png"/>. <HighResolutionIconUrl DefaultValue="https://ultra.ally.staging.riverus.io/assets/riverus-short-logo.png"/>. <SupportUrl DefaultValue="https://www.riverus.in/help"/>. <AppDomains>. <AppDomain>https://ultra.ally.staging.riverus.io</AppDomain>. <Ap
                                    No static file info
                                    TimestampSource PortDest PortSource IPDest IP
                                    Apr 19, 2024 17:01:18.636624098 CEST49675443192.168.2.4173.222.162.32
                                    Apr 19, 2024 17:01:28.245981932 CEST49675443192.168.2.4173.222.162.32
                                    Apr 19, 2024 17:01:30.954314947 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.954365015 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:30.954449892 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.954705954 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.954744101 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:30.954900026 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.954920053 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:30.954931974 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.955140114 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:30.955148935 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.203447104 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.203752041 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.203778028 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.205027103 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.205097914 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.206204891 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.206279993 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.206438065 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.206445932 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.209938049 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.210131884 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.210158110 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.211585999 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.211644888 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.212466002 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.212538004 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.248729944 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.263762951 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.263776064 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.308890104 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.432225943 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.432343006 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.432440996 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.432470083 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.432514906 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.432832956 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.433317900 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.433402061 CEST44349736108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.433465004 CEST49736443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.556864023 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.600127935 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.759556055 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.759829998 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:31.759891987 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.777148008 CEST49735443192.168.2.4108.138.64.65
                                    Apr 19, 2024 17:01:31.777184010 CEST44349735108.138.64.65192.168.2.4
                                    Apr 19, 2024 17:01:33.170928001 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.170972109 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.171051979 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.173559904 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.173574924 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.399708033 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.429018974 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.429037094 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.433707952 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.433788061 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.435312986 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.435728073 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.479381084 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.479413986 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:33.526227951 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:33.609177113 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.609220028 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:33.609452963 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.611845016 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.611860037 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:33.839349985 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:33.839445114 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.845652103 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.845696926 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:33.846004963 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:33.901242971 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.932907104 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:33.976125002 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.038330078 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.038407087 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.038486004 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.038680077 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.038723946 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.038749933 CEST49740443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.038767099 CEST4434974023.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.078599930 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.078646898 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.078780890 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.079169035 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.079180002 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.295977116 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.296055079 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.297518969 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.297528028 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.297768116 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.298919916 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.344118118 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.507170916 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.507262945 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.507317066 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.512058020 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.512080908 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:34.512090921 CEST49741443192.168.2.423.197.2.6
                                    Apr 19, 2024 17:01:34.512096882 CEST4434974123.197.2.6192.168.2.4
                                    Apr 19, 2024 17:01:41.270049095 CEST49672443192.168.2.4173.222.162.32
                                    Apr 19, 2024 17:01:41.270098925 CEST44349672173.222.162.32192.168.2.4
                                    Apr 19, 2024 17:01:43.394334078 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:43.394422054 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:01:43.394479990 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:45.054928064 CEST49739443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:01:45.054956913 CEST44349739172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.106924057 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:33.106966019 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.107136965 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:33.107873917 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:33.107897997 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.327625990 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.328041077 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:33.328052044 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.329170942 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.329755068 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:33.329927921 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:33.370201111 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:34.136048079 CEST4972380192.168.2.423.40.205.11
                                    Apr 19, 2024 17:02:34.136343956 CEST4972480192.168.2.4199.232.214.172
                                    Apr 19, 2024 17:02:34.244075060 CEST8049724199.232.214.172192.168.2.4
                                    Apr 19, 2024 17:02:34.244096994 CEST8049724199.232.214.172192.168.2.4
                                    Apr 19, 2024 17:02:34.244124889 CEST804972323.40.205.11192.168.2.4
                                    Apr 19, 2024 17:02:34.244157076 CEST4972480192.168.2.4199.232.214.172
                                    Apr 19, 2024 17:02:34.244189978 CEST4972380192.168.2.423.40.205.11
                                    Apr 19, 2024 17:02:43.329519987 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:43.329663992 CEST44349750172.253.124.147192.168.2.4
                                    Apr 19, 2024 17:02:43.329752922 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:45.029529095 CEST49750443192.168.2.4172.253.124.147
                                    Apr 19, 2024 17:02:45.029560089 CEST44349750172.253.124.147192.168.2.4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Apr 19, 2024 17:01:28.911741018 CEST53572601.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:28.918658018 CEST53552791.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:29.515409946 CEST53526931.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:30.739821911 CEST5741653192.168.2.41.1.1.1
                                    Apr 19, 2024 17:01:30.740036964 CEST5030153192.168.2.41.1.1.1
                                    Apr 19, 2024 17:01:30.952436924 CEST53503011.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:30.953464031 CEST53574161.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:33.046027899 CEST4944253192.168.2.41.1.1.1
                                    Apr 19, 2024 17:01:33.046319962 CEST5450553192.168.2.41.1.1.1
                                    Apr 19, 2024 17:01:33.150950909 CEST53494421.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:33.150975943 CEST53545051.1.1.1192.168.2.4
                                    Apr 19, 2024 17:01:45.704854012 CEST138138192.168.2.4192.168.2.255
                                    Apr 19, 2024 17:01:47.066117048 CEST53628441.1.1.1192.168.2.4
                                    Apr 19, 2024 17:02:06.008686066 CEST53603861.1.1.1192.168.2.4
                                    Apr 19, 2024 17:02:28.551078081 CEST53646961.1.1.1192.168.2.4
                                    Apr 19, 2024 17:02:28.794311047 CEST53496781.1.1.1192.168.2.4
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Apr 19, 2024 17:01:30.739821911 CEST192.168.2.41.1.1.10x2aaStandard query (0)ultra.ally.staging.riverus.ioA (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.740036964 CEST192.168.2.41.1.1.10x8a94Standard query (0)ultra.ally.staging.riverus.io65IN (0x0001)false
                                    Apr 19, 2024 17:01:33.046027899 CEST192.168.2.41.1.1.10x388eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.046319962 CEST192.168.2.41.1.1.10xbcb1Standard query (0)www.google.com65IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Apr 19, 2024 17:01:30.952436924 CEST1.1.1.1192.168.2.40x8a94No error (0)ultra.ally.staging.riverus.iod15cg09v7rb8cb.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.953464031 CEST1.1.1.1192.168.2.40x2aaNo error (0)ultra.ally.staging.riverus.iod15cg09v7rb8cb.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.953464031 CEST1.1.1.1192.168.2.40x2aaNo error (0)d15cg09v7rb8cb.cloudfront.net108.138.64.65A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.953464031 CEST1.1.1.1192.168.2.40x2aaNo error (0)d15cg09v7rb8cb.cloudfront.net108.138.64.119A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.953464031 CEST1.1.1.1192.168.2.40x2aaNo error (0)d15cg09v7rb8cb.cloudfront.net108.138.64.12A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:30.953464031 CEST1.1.1.1192.168.2.40x2aaNo error (0)d15cg09v7rb8cb.cloudfront.net108.138.64.50A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.147A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.104A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.103A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.106A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.99A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150950909 CEST1.1.1.1192.168.2.40x388eNo error (0)www.google.com172.253.124.105A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:33.150975943 CEST1.1.1.1192.168.2.40xbcb1No error (0)www.google.com65IN (0x0001)false
                                    Apr 19, 2024 17:01:41.922374010 CEST1.1.1.1192.168.2.40xb97eNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:41.922374010 CEST1.1.1.1192.168.2.40xb97eNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:43.032202005 CEST1.1.1.1192.168.2.40xe2ceNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:01:43.032202005 CEST1.1.1.1192.168.2.40xe2ceNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:01:55.740509987 CEST1.1.1.1192.168.2.40x83c0No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:01:55.740509987 CEST1.1.1.1192.168.2.40x83c0No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:02:21.226267099 CEST1.1.1.1192.168.2.40x9d07No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:02:21.226267099 CEST1.1.1.1192.168.2.40x9d07No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                    Apr 19, 2024 17:02:41.827090025 CEST1.1.1.1192.168.2.40x307eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                    Apr 19, 2024 17:02:41.827090025 CEST1.1.1.1192.168.2.40x307eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                    • ultra.ally.staging.riverus.io
                                    • https:
                                    • fs.microsoft.com
                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                    0192.168.2.449736108.138.64.65443888C:\Program Files\Google\Chrome\Application\chrome.exe
                                    TimestampBytes transferredDirectionData
                                    2024-04-19 15:01:31 UTC672OUTGET / HTTP/1.1
                                    Host: ultra.ally.staging.riverus.io
                                    Connection: keep-alive
                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                    sec-ch-ua-mobile: ?0
                                    sec-ch-ua-platform: "Windows"
                                    Upgrade-Insecure-Requests: 1
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                    Sec-Fetch-Site: none
                                    Sec-Fetch-Mode: navigate
                                    Sec-Fetch-User: ?1
                                    Sec-Fetch-Dest: document
                                    Accept-Encoding: gzip, deflate, br
                                    Accept-Language: en-US,en;q=0.9
                                    2024-04-19 15:01:31 UTC500INHTTP/1.1 200 OK
                                    Content-Type: application/xml
                                    Content-Length: 4325
                                    Connection: close
                                    Date: Fri, 19 Apr 2024 14:58:04 GMT
                                    Last-Modified: Thu, 11 Apr 2024 17:02:26 GMT
                                    ETag: "b11c60ad7db09c6dbdc8b9ba7bec8681"
                                    x-amz-server-side-encryption: AES256
                                    Accept-Ranges: bytes
                                    Server: AmazonS3
                                    X-Cache: Hit from cloudfront
                                    Via: 1.1 5988b4ae4648c0fec3c60a3cca580092.cloudfront.net (CloudFront)
                                    X-Amz-Cf-Pop: IAD12-P1
                                    X-Amz-Cf-Id: 1QtBaH4_TydDvBPl5rcgCaNxv7d3H1Rc-Ec28NR-mQZQoRzCvcUZHw==
                                    Age: 208
                                    2024-04-19 15:01:31 UTC3198INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 20 73 74 61 6e 64 61 6c 6f 6e 65 3d 22 79 65 73 22 3f 3e 0a 3c 4f 66 66 69 63 65 41 70 70 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 6f 66 66 69 63 65 2f 61 70 70 66 6f 72 6f 66 66 69 63 65 2f 31 2e 31 22 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 62 74 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 6f 66 66 69 63 65 2f 6f 66 66 69 63 65 61 70 70 62 61 73 69 63 74 79 70 65 73 2f 31 2e 30 22 20 78 6d
                                    Data Ascii: <?xml version="1.0" encoding="UTF-8" standalone="yes"?><OfficeApp xmlns="http://schemas.microsoft.com/office/appforoffice/1.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:bt="http://schemas.microsoft.com/office/officeappbasictypes/1.0" xm
                                    2024-04-19 15:01:31 UTC1127INData Raw: 6d 61 67 65 20 69 64 3d 22 49 63 6f 6e 2e 33 32 78 33 32 22 20 44 65 66 61 75 6c 74 56 61 6c 75 65 3d 22 68 74 74 70 73 3a 2f 2f 75 6c 74 72 61 2e 61 6c 6c 79 2e 73 74 61 67 69 6e 67 2e 72 69 76 65 72 75 73 2e 69 6f 2f 61 73 73 65 74 73 2f 69 63 6f 6e 2d 33 32 2e 70 6e 67 22 2f 3e 0a 20 20 20 20 20 20 20 20 3c 62 74 3a 49 6d 61 67 65 20 69 64 3d 22 49 63 6f 6e 2e 38 30 78 38 30 22 20 44 65 66 61 75 6c 74 56 61 6c 75 65 3d 22 68 74 74 70 73 3a 2f 2f 75 6c 74 72 61 2e 61 6c 6c 79 2e 73 74 61 67 69 6e 67 2e 72 69 76 65 72 75 73 2e 69 6f 2f 61 73 73 65 74 73 2f 69 63 6f 6e 2d 38 30 2e 70 6e 67 22 2f 3e 0a 20 20 20 20 20 20 3c 2f 62 74 3a 49 6d 61 67 65 73 3e 0a 20 20 20 20 20 20 3c 62 74 3a 55 72 6c 73 3e 0a 20 20 20 20 20 20 20 20 3c 62 74 3a 55 72 6c 20 69
                                    Data Ascii: mage id="Icon.32x32" DefaultValue="https://ultra.ally.staging.riverus.io/assets/icon-32.png"/> <bt:Image id="Icon.80x80" DefaultValue="https://ultra.ally.staging.riverus.io/assets/icon-80.png"/> </bt:Images> <bt:Urls> <bt:Url i


                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                    1192.168.2.449735108.138.64.65443888C:\Program Files\Google\Chrome\Application\chrome.exe
                                    TimestampBytes transferredDirectionData
                                    2024-04-19 15:01:31 UTC614OUTGET /favicon.ico HTTP/1.1
                                    Host: ultra.ally.staging.riverus.io
                                    Connection: keep-alive
                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                    sec-ch-ua-mobile: ?0
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                    sec-ch-ua-platform: "Windows"
                                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                    Sec-Fetch-Site: same-origin
                                    Sec-Fetch-Mode: no-cors
                                    Sec-Fetch-Dest: image
                                    Referer: https://ultra.ally.staging.riverus.io/
                                    Accept-Encoding: gzip, deflate, br
                                    Accept-Language: en-US,en;q=0.9
                                    2024-04-19 15:01:31 UTC357INHTTP/1.1 404 Not Found
                                    Content-Type: application/xml
                                    Transfer-Encoding: chunked
                                    Connection: close
                                    Date: Fri, 19 Apr 2024 15:01:31 GMT
                                    Server: AmazonS3
                                    X-Cache: Error from cloudfront
                                    Via: 1.1 7eeed291abf48890d3f36565208941a8.cloudfront.net (CloudFront)
                                    X-Amz-Cf-Pop: IAD12-P1
                                    X-Amz-Cf-Id: kbDN7CbJ6JgzT3-FLVkkQA3TA_r9vRmnc1S5hzQg4TUoruYU8NfZgw==
                                    2024-04-19 15:01:31 UTC289INData Raw: 31 31 61 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 0a 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 4e 6f 53 75 63 68 4b 65 79 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 54 68 65 20 73 70 65 63 69 66 69 65 64 20 6b 65 79 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 4b 65 79 3e 66 61 76 69 63 6f 6e 2e 69 63 6f 3c 2f 4b 65 79 3e 3c 52 65 71 75 65 73 74 49 64 3e 4a 37 31 52 35 32 32 37 53 48 4e 50 50 4b 5a 41 3c 2f 52 65 71 75 65 73 74 49 64 3e 3c 48 6f 73 74 49 64 3e 6c 47 38 37 61 55 7a 66 2f 4a 64 59 4f 2b 64 53 72 4a 77 46 57 62 65 53 53 57 4c 51 2f 46 4e 76 53 33 46 4d 52 62 48 35 67 63 58 59 52 69 30 68 6c 47 72 57 52 45 4b 63 6f 72 41 57 42
                                    Data Ascii: 11a<?xml version="1.0" encoding="UTF-8"?><Error><Code>NoSuchKey</Code><Message>The specified key does not exist.</Message><Key>favicon.ico</Key><RequestId>J71R5227SHNPPKZA</RequestId><HostId>lG87aUzf/JdYO+dSrJwFWbeSSWLQ/FNvS3FMRbH5gcXYRi0hlGrWREKcorAWB
                                    2024-04-19 15:01:31 UTC5INData Raw: 30 0d 0a 0d 0a
                                    Data Ascii: 0


                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                    2192.168.2.44974023.197.2.6443
                                    TimestampBytes transferredDirectionData
                                    2024-04-19 15:01:33 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                    Connection: Keep-Alive
                                    Accept: */*
                                    Accept-Encoding: identity
                                    User-Agent: Microsoft BITS/7.8
                                    Host: fs.microsoft.com
                                    2024-04-19 15:01:34 UTC467INHTTP/1.1 200 OK
                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                    Content-Type: application/octet-stream
                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                    Server: ECAcc (chd/073D)
                                    X-CID: 11
                                    X-Ms-ApiVersion: Distribute 1.2
                                    X-Ms-Region: prod-eus-z1
                                    Cache-Control: public, max-age=144168
                                    Date: Fri, 19 Apr 2024 15:01:33 GMT
                                    Connection: close
                                    X-CID: 2


                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                    3192.168.2.44974123.197.2.6443
                                    TimestampBytes transferredDirectionData
                                    2024-04-19 15:01:34 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                    Connection: Keep-Alive
                                    Accept: */*
                                    Accept-Encoding: identity
                                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                    Range: bytes=0-2147483646
                                    User-Agent: Microsoft BITS/7.8
                                    Host: fs.microsoft.com
                                    2024-04-19 15:01:34 UTC660INHTTP/1.1 200 OK
                                    Content-Type: application/octet-stream
                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                    ApiVersion: Distribute 1.1
                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                    X-CID: 7
                                    X-CCC: US
                                    X-Azure-Ref-OriginShield: Ref A: 974286BFDC254CDCB50C2B73CC4B4276 Ref B: MNZ221060605025 Ref C: 2023-03-13T15:26:50Z
                                    X-MSEdge-Ref: Ref A: 87B54C6474A14C81B6E546C3B6B2F842 Ref B: BLUEDGE1720 Ref C: 2023-03-13T15:26:50Z
                                    Cache-Control: public, max-age=144115
                                    Date: Fri, 19 Apr 2024 15:01:34 GMT
                                    Content-Length: 55
                                    Connection: close
                                    X-CID: 2
                                    2024-04-19 15:01:34 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                    Click to jump to process

                                    Click to jump to process

                                    Click to jump to process

                                    Target ID:0
                                    Start time:17:01:23
                                    Start date:19/04/2024
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                                    Imagebase:0x7ff76e190000
                                    File size:3'242'272 bytes
                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Target ID:2
                                    Start time:17:01:27
                                    Start date:19/04/2024
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2236 --field-trial-handle=2200,i,10461123817870828047,4255301424661301404,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                    Imagebase:0x7ff76e190000
                                    File size:3'242'272 bytes
                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Target ID:3
                                    Start time:17:01:30
                                    Start date:19/04/2024
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ultra.ally.staging.riverus.io/"
                                    Imagebase:0x7ff76e190000
                                    File size:3'242'272 bytes
                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:true

                                    No disassembly