Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6

Overview

General Information

Sample URL:https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9Btpq
Analysis ID:1430203
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

URL contains potential PII (phishing indication)

Classification

  • System is w10x64
  • chrome.exe (PID: 4940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2028,i,15326543560496755507,3115035497610140098,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.comSample URL: PII: sales1@aaazxy.com
Source: https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.comHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.193.120.112
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com HTTP/1.1Host: lx-pluto-mail.qiye.163.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: lx-pluto-mail.qiye.163.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.comAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: lx-pluto-mail.qiye.163.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.20.1Date: Tue, 23 Apr 2024 08:11:55 GMTContent-Length: 0Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.193.120.112:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2028,i,15326543560496755507,3115035497610140098,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2028,i,15326543560496755507,3115035497610140098,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    lx-pluto-mail.qiye.163.com
    47.243.189.198
    truefalse
      high
      www.google.com
      142.250.105.147
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://lx-pluto-mail.qiye.163.com/favicon.icofalse
            high
            https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.comfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              47.243.189.198
              lx-pluto-mail.qiye.163.comUnited States
              45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
              142.250.105.147
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1430203
              Start date and time:2024-04-23 10:10:54 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 17s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/2@4/4
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 64.233.185.94, 142.250.105.101, 142.250.105.113, 142.250.105.139, 142.250.105.138, 142.250.105.100, 142.250.105.102, 173.194.219.84, 34.104.35.123, 172.253.124.95, 142.250.9.95, 142.250.105.95, 108.177.122.95, 64.233.177.95, 74.125.138.95, 64.233.176.95, 142.251.15.95, 172.217.215.95, 74.125.136.95, 64.233.185.95, 173.194.219.95, 13.85.23.86, 199.232.214.172, 20.242.39.171, 192.229.211.108, 52.165.164.15, 173.194.219.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with no line terminators
              Category:downloaded
              Size (bytes):16
              Entropy (8bit):3.625
              Encrypted:false
              SSDEEP:3:HFn:l
              MD5:418FBC40DEEBD999D02A91F3BC9850B9
              SHA1:A04AB7C83CB2CDF175711BF34C27A0C32F801DC2
              SHA-256:E85E233CE28065F9DE8A6429A42B6BFC4752340EDB2F66AF1B79F1B805549771
              SHA-512:74599CE0567379C67882DCC387D869C2F5340D5F814789A65740C378A85949822118A4C8B842241D297087907CF646271DAB0866E3754291F729C3253185986D
              Malicious:false
              Reputation:low
              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAksNXZu33NQFBIFDWXnCSY=?alt=proto
              Preview:CgkKBw1l5wkmGgA=
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 23, 2024 10:11:43.089500904 CEST49675443192.168.2.4173.222.162.32
              Apr 23, 2024 10:11:52.806611061 CEST49675443192.168.2.4173.222.162.32
              Apr 23, 2024 10:11:53.090567112 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.090620041 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:53.091185093 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.091284990 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.091367960 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:53.091487885 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.091499090 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:53.091691971 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.091800928 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:53.091833115 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.032653093 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.033113956 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.033171892 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.034842014 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.034941912 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.036078930 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.036194086 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.036271095 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.055751085 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.055991888 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.056009054 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.057446003 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.057513952 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.057936907 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.058012962 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.080161095 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.089370966 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.089427948 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.104625940 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.104657888 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.134727955 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.150564909 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.782011032 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782095909 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782115936 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782149076 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782171011 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.782238007 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782273054 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.782295942 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:54.782360077 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.783716917 CEST49737443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:54.783761024 CEST4434973747.243.189.198192.168.2.4
              Apr 23, 2024 10:11:55.082786083 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:55.128110886 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:55.470841885 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:55.470916033 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:55.470962048 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:55.471771002 CEST49736443192.168.2.447.243.189.198
              Apr 23, 2024 10:11:55.471784115 CEST4434973647.243.189.198192.168.2.4
              Apr 23, 2024 10:11:56.269036055 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.269114971 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.269197941 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.269593954 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.269635916 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.491633892 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.491981983 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.492049932 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.493513107 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.493596077 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.495382071 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.495471954 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.541006088 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.541064978 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:11:56.587908983 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:11:56.592761993 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:56.592840910 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:56.592936039 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:56.595535994 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:56.595613956 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:56.848062038 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:56.848203897 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:56.853766918 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:56.853840113 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:56.854278088 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:56.900293112 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.000750065 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.044198990 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.125530958 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.125670910 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.125883102 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.125962019 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.125999928 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.126040936 CEST49742443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.126059055 CEST4434974223.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.172982931 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.173060894 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.173146963 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.173399925 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.173424959 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.423639059 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.423739910 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.425065994 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.425116062 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.426237106 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.427366018 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.468151093 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.700521946 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.700680017 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.700860977 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.758580923 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.758582115 CEST49743443192.168.2.423.193.120.112
              Apr 23, 2024 10:11:57.758644104 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:11:57.758680105 CEST4434974323.193.120.112192.168.2.4
              Apr 23, 2024 10:12:06.506076097 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:06.506134033 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:06.506217003 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:07.125658989 CEST4972380192.168.2.472.21.81.240
              Apr 23, 2024 10:12:07.229932070 CEST804972372.21.81.240192.168.2.4
              Apr 23, 2024 10:12:07.230098963 CEST4972380192.168.2.472.21.81.240
              Apr 23, 2024 10:12:08.063313007 CEST49741443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:08.063374996 CEST44349741142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.212429047 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.212467909 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.212538004 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.212745905 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.212757111 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.426208973 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.426493883 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.426506042 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.426830053 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.427303076 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.427357912 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:12:56.476862907 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:12:56.523840904 CEST4972480192.168.2.472.21.81.240
              Apr 23, 2024 10:12:56.628074884 CEST804972472.21.81.240192.168.2.4
              Apr 23, 2024 10:12:56.628161907 CEST4972480192.168.2.472.21.81.240
              Apr 23, 2024 10:13:06.434138060 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:13:06.434216976 CEST44349751142.250.105.147192.168.2.4
              Apr 23, 2024 10:13:06.434271097 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:13:08.284333944 CEST49751443192.168.2.4142.250.105.147
              Apr 23, 2024 10:13:08.284369946 CEST44349751142.250.105.147192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 23, 2024 10:11:51.615274906 CEST53607441.1.1.1192.168.2.4
              Apr 23, 2024 10:11:51.848200083 CEST53555591.1.1.1192.168.2.4
              Apr 23, 2024 10:11:52.383507013 CEST53627461.1.1.1192.168.2.4
              Apr 23, 2024 10:11:52.953012943 CEST4991053192.168.2.41.1.1.1
              Apr 23, 2024 10:11:52.953303099 CEST6460553192.168.2.41.1.1.1
              Apr 23, 2024 10:11:53.058372974 CEST53499101.1.1.1192.168.2.4
              Apr 23, 2024 10:11:53.128767967 CEST53646051.1.1.1192.168.2.4
              Apr 23, 2024 10:11:55.128464937 CEST53630611.1.1.1192.168.2.4
              Apr 23, 2024 10:11:56.162386894 CEST5368253192.168.2.41.1.1.1
              Apr 23, 2024 10:11:56.162542105 CEST6038853192.168.2.41.1.1.1
              Apr 23, 2024 10:11:56.267488956 CEST53603881.1.1.1192.168.2.4
              Apr 23, 2024 10:11:56.267628908 CEST53536821.1.1.1192.168.2.4
              Apr 23, 2024 10:12:08.232599974 CEST138138192.168.2.4192.168.2.255
              Apr 23, 2024 10:12:09.758409977 CEST53494301.1.1.1192.168.2.4
              Apr 23, 2024 10:12:28.616936922 CEST53633321.1.1.1192.168.2.4
              Apr 23, 2024 10:12:51.415617943 CEST53560641.1.1.1192.168.2.4
              Apr 23, 2024 10:12:51.603157043 CEST53558471.1.1.1192.168.2.4
              TimestampSource IPDest IPChecksumCodeType
              Apr 23, 2024 10:11:53.128878117 CEST192.168.2.41.1.1.1c227(Port unreachable)Destination Unreachable
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 23, 2024 10:11:52.953012943 CEST192.168.2.41.1.1.10xab51Standard query (0)lx-pluto-mail.qiye.163.comA (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:52.953303099 CEST192.168.2.41.1.1.10x93f0Standard query (0)lx-pluto-mail.qiye.163.com65IN (0x0001)false
              Apr 23, 2024 10:11:56.162386894 CEST192.168.2.41.1.1.10x8706Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.162542105 CEST192.168.2.41.1.1.10xa4a9Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 23, 2024 10:11:53.058372974 CEST1.1.1.1192.168.2.40xab51No error (0)lx-pluto-mail.qiye.163.com47.243.189.198A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267488956 CEST1.1.1.1192.168.2.40xa4a9No error (0)www.google.com65IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.147A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.105A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.103A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.104A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.106A (IP address)IN (0x0001)false
              Apr 23, 2024 10:11:56.267628908 CEST1.1.1.1192.168.2.40x8706No error (0)www.google.com142.250.105.99A (IP address)IN (0x0001)false
              Apr 23, 2024 10:12:06.807416916 CEST1.1.1.1192.168.2.40xf32cNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Apr 23, 2024 10:12:06.807416916 CEST1.1.1.1192.168.2.40xf32cNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Apr 23, 2024 10:12:07.832878113 CEST1.1.1.1192.168.2.40xe3cdNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 23, 2024 10:12:07.832878113 CEST1.1.1.1192.168.2.40xe3cdNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 23, 2024 10:12:24.836474895 CEST1.1.1.1192.168.2.40x107fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 23, 2024 10:12:24.836474895 CEST1.1.1.1192.168.2.40x107fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 23, 2024 10:12:43.729027987 CEST1.1.1.1192.168.2.40xb1deNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 23, 2024 10:12:43.729027987 CEST1.1.1.1192.168.2.40xb1deNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 23, 2024 10:13:04.490606070 CEST1.1.1.1192.168.2.40xb4eeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 23, 2024 10:13:04.490606070 CEST1.1.1.1192.168.2.40xb4eeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • lx-pluto-mail.qiye.163.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973747.243.189.1984431508C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-23 08:11:54 UTC959OUTGET /unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com HTTP/1.1
              Host: lx-pluto-mail.qiye.163.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-23 08:11:54 UTC471INHTTP/1.1 200 OK
              Server: nginx/1.20.1
              Date: Tue, 23 Apr 2024 08:11:54 GMT
              Content-Type: text/html
              Content-Length: 8415
              Connection: close
              last-modified: Mon, 22 Apr 2024 05:54:32 GMT
              accept-ranges: bytes
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block
              cache-control: no-cache, no-store, max-age=0, must-revalidate
              pragma: no-cache
              expires: 0
              x-envoy-upstream-service-time: 5
              lingxi-traceid: cc07dd2787c640aa8db97599^1697544321554^780329036
              2024-04-23 08:11:54 UTC8415INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 3c 74 69 74 6c 65 3e e7 bd 91 e6 98 93 e7 81 b5 e7 8a 80 e5 8a 9e e5 85 ac 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 20 20 20 20 68 74 6d 6c 2c 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20
              Data Ascii: <!DOCTYPE html><html><head> <meta charset="UTF-8"> <title></title> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /> <style> html, body { margin: 0;


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973647.243.189.1984431508C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-23 08:11:55 UTC898OUTGET /favicon.ico HTTP/1.1
              Host: lx-pluto-mail.qiye.163.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-23 08:11:55 UTC123INHTTP/1.1 404 Not Found
              Server: nginx/1.20.1
              Date: Tue, 23 Apr 2024 08:11:55 GMT
              Content-Length: 0
              Connection: close


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.44974223.193.120.112443
              TimestampBytes transferredDirectionData
              2024-04-23 08:11:56 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-23 08:11:57 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/079C)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus2-z1
              Cache-Control: public, max-age=82296
              Date: Tue, 23 Apr 2024 08:11:57 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.44974323.193.120.112443
              TimestampBytes transferredDirectionData
              2024-04-23 08:11:57 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-23 08:11:57 UTC530INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-Azure-Ref: 0DZ+oYgAAAABSxwJpMgMuSLkfS640ajfFQVRBRURHRTEyMTkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=82243
              Date: Tue, 23 Apr 2024 08:11:57 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-23 08:11:57 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:10:11:46
              Start date:23/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:10:11:50
              Start date:23/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2028,i,15326543560496755507,3115035497610140098,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:10:11:52
              Start date:23/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lx-pluto-mail.qiye.163.com/unsubscribe_en.html?host=lx-pluto-mail.qiye.163.com&sign=tYjJWFMjS3nn3YqvszWFhdv6S7f427CtlG6Qc97yX%2BvgJErYHlag8awX2vfVi%2B12IzWnpp72Z4Ca%0AxsG5%2Bb9mDQ30Lmqfrm9BtpqSiq7XoI%2BjidChX5ytHSJuo9hhv57eCMVHyi2xsxwIEr5x9dnZ3p3o%0ApGb7ImP4SgjKiKpbhL%2F7d1aI4fC5%2Fbj4bOQCi6jm&from=sales1@aaazxy.com"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly