Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email

Overview

General Information

Sample URL:https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email
Analysis ID:1430831
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 764 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1940,i,8437511569128404353,3104943773025343623,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6496 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=emailHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email HTTP/1.1Host: app.firmway.inConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: app.firmway.inConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjcxSjdUT3lIdXN5bDlYWkFTUGI1Q1E9PSIsInZhbHVlIjoiVHppSjdabHA5bk8yNzFvS05pN1dXbWpCRStQaDNJTDRHVGozaXpHQ0Q0dm5DZlNPcEpzNjVZVURpbkMwTGxONVFzbFA4Q3hwQWpJczA2VHcra2ltV29NaUJSM0t1Vk1maE9EeWZwS1wvKzRpQWt0dzVzS1JKVmZzb2pwVVpOdHdBIiwibWFjIjoiMWUxOTc0ODZlZTAxNTkyYWIyZTMyYWMzZjViMjU4MDI0Y2U0NDZkNzI4ZmM5ZWI5ZGZhYWI5NGE1YWUyNGZhMiJ9; laravel_session=rBZXXukE7yMtqL1ef6T8u1XHldjRM4y2lQxkTvBE
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: app.firmway.inConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IjcxSjdUT3lIdXN5bDlYWkFTUGI1Q1E9PSIsInZhbHVlIjoiVHppSjdabHA5bk8yNzFvS05pN1dXbWpCRStQaDNJTDRHVGozaXpHQ0Q0dm5DZlNPcEpzNjVZVURpbkMwTGxONVFzbFA4Q3hwQWpJczA2VHcra2ltV29NaUJSM0t1Vk1maE9EeWZwS1wvKzRpQWt0dzVzS1JKVmZzb2pwVVpOdHdBIiwibWFjIjoiMWUxOTc0ODZlZTAxNTkyYWIyZTMyYWMzZjViMjU4MDI0Y2U0NDZkNzI4ZmM5ZWI5ZGZhYWI5NGE1YWUyNGZhMiJ9; laravel_session=rBZXXukE7yMtqL1ef6T8u1XHldjRM4y2lQxkTvBE
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: app.firmway.in
Source: unknownHTTP traffic detected: POST /report/v4?s=xTsQDMLkVmb%2FlG7KG2bum3xecQ8Xhy9%2BsbKqS%2BzPIJceK2gkp1W71pHAFlzR6M2Jkewp6JIyHuwoW%2Boc7bk%2FIq4Oi6NwuwyH7k0K%2FOSfoMrrmRazC1YoyDaYiGNMaWhj%2BA%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 494Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.4:49745 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1940,i,8437511569128404353,3104943773025343623,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1940,i,8437511569128404353,3104943773025343623,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email0%Avira URL Cloudsafe
https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://app.firmway.in/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    app.firmway.in
    172.67.154.86
    truefalse
      unknown
      a.nel.cloudflare.com
      35.190.80.1
      truefalse
        high
        www.google.com
        142.250.101.99
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://app.firmway.in/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://a.nel.cloudflare.com/report/v4?s=xTsQDMLkVmb%2FlG7KG2bum3xecQ8Xhy9%2BsbKqS%2BzPIJceK2gkp1W71pHAFlzR6M2Jkewp6JIyHuwoW%2Boc7bk%2FIq4Oi6NwuwyH7k0K%2FOSfoMrrmRazC1YoyDaYiGNMaWhj%2BA%3D%3Dfalse
              high
              https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=emailfalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.101.99
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                172.67.154.86
                app.firmway.inUnited States
                13335CLOUDFLARENETUSfalse
                104.21.48.162
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1430831
                Start date and time:2024-04-24 09:27:25 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 19s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@16/2@8/6
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.113, 142.251.2.138, 142.251.2.101, 142.251.2.102, 142.251.2.139, 142.251.2.100, 142.251.2.84, 34.104.35.123, 52.165.165.26, 23.1.234.57, 23.1.234.24, 192.229.211.108, 13.85.23.206, 199.232.214.172, 142.250.101.94, 74.125.137.113, 74.125.137.138, 74.125.137.101, 74.125.137.139, 74.125.137.102, 74.125.137.100
                • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):630
                Entropy (8bit):4.627016413245974
                Encrypted:false
                SSDEEP:12:hYcN1IiEXMqBrp/DTxFz0RXfjcaEdMlkDkHAWoQb:hYcN7EXFBrdBFMXfcOGs
                MD5:478D0A8868FD5CEC3C781F788E9A3353
                SHA1:D1FA9CBBE30C23D416C46A0566F963CA29704036
                SHA-256:1ACE16EC43923C0D93BBF2802C56E49C4E2EDAFCE856E5617A6200C1F261A8AF
                SHA-512:25D2B0F7418C970E0A347C2A40A8CBE9D0E6E40467BA249DF1DF9FB8BA5A0E46B2F6CC22F68E748C4F0B0D04BF5014D9A7CF2DE228997A6522DB1DDA36283673
                Malicious:false
                Reputation:low
                URL:https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email
                Preview:<!DOCTYPE html>.<html>. <head>. <meta charset="UTF-8" />. <meta name="robots" content="noindex,nofollow" />. <style> body { background-color: #fff; color: #222; font: 16px/1.5 -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif; margin: 0; }. .container { margin: 30px; max-width: 600px; }. h1 { color: #dc3545; font-size: 24px; }</style>. </head>. <body>. <div class="container">. <h1>Whoops, looks like something went wrong.</h1>. </div>. </body>.</html>
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 24, 2024 09:28:08.054733038 CEST49678443192.168.2.4104.46.162.224
                Apr 24, 2024 09:28:10.132760048 CEST49675443192.168.2.4173.222.162.32
                Apr 24, 2024 09:28:17.664154053 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.664241076 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:17.664330006 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.664788008 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.664853096 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:17.664933920 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.665122032 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.665159941 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:17.665282011 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:17.665311098 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.001976967 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.002430916 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.002456903 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.003026009 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.003231049 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.003271103 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.004117966 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.004193068 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.004815102 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.004893064 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.005544901 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.005635023 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.005966902 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.005975962 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.006155014 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.006243944 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.057221889 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.057228088 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:18.057241917 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:18.104490995 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:19.415721893 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:19.415975094 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:19.416234016 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:19.416327953 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:19.419094086 CEST49735443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:19.419137955 CEST44349735172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:19.576816082 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:19.576850891 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:19.576911926 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:19.577182055 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:19.577193975 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:19.732737064 CEST49675443192.168.2.4173.222.162.32
                Apr 24, 2024 09:28:19.940453053 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:19.940741062 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:19.940762043 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:19.942497015 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:19.942564011 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.004350901 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:20.005516052 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.005831003 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.005842924 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.048146009 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:20.050741911 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.050761938 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.102606058 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.319406986 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.319587946 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.319650888 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.321902990 CEST49739443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.321928024 CEST4434973935.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.323141098 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.323224068 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.323318958 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.324091911 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.324141979 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.335087061 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.335118055 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.335258007 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.336033106 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.336045027 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.674299955 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.676929951 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.676975012 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.678107977 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.683840036 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.684039116 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.684412956 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:20.697690964 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.732119083 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:20.741112947 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.767177105 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.767191887 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.768920898 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.768995047 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.781111002 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.781208992 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.834860086 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:20.834880114 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:20.881751060 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:21.067995071 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:21.068233013 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:21.068300962 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:21.069273949 CEST49740443192.168.2.435.190.80.1
                Apr 24, 2024 09:28:21.069310904 CEST4434974035.190.80.1192.168.2.4
                Apr 24, 2024 09:28:21.085589886 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.085654020 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.085767984 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.089091063 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.089127064 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.376261950 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:21.376435995 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:21.376549959 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:21.377019882 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:21.377064943 CEST44349736172.67.154.86192.168.2.4
                Apr 24, 2024 09:28:21.377118111 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:21.377140999 CEST49736443192.168.2.4172.67.154.86
                Apr 24, 2024 09:28:21.451327085 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.451406002 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.454027891 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.454047918 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.454458952 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.506745100 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.515625000 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.560127974 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.754667044 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:21.754750013 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:21.754839897 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:21.755100012 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:21.755124092 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:21.768932104 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.769025087 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.769093990 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.769241095 CEST49743443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.769270897 CEST4434974323.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.955365896 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.955398083 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:21.955565929 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.956521988 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:21.956535101 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.087363958 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.087735891 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.087795973 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.089492083 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.089608908 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.090581894 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.090830088 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.090949059 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.090985060 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.131884098 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.299529076 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.299629927 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.302337885 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.302347898 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.302855968 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.304974079 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.348131895 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.458233118 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.458389997 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.458580017 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.459345102 CEST49744443192.168.2.4104.21.48.162
                Apr 24, 2024 09:28:22.459405899 CEST44349744104.21.48.162192.168.2.4
                Apr 24, 2024 09:28:22.636848927 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.637027979 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.637283087 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.637851954 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.637851954 CEST49745443192.168.2.423.202.57.177
                Apr 24, 2024 09:28:22.637870073 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:22.637881041 CEST4434974523.202.57.177192.168.2.4
                Apr 24, 2024 09:28:30.706942081 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:30.707020044 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:28:30.707087040 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:32.399682999 CEST49741443192.168.2.4142.250.101.99
                Apr 24, 2024 09:28:32.399707079 CEST44349741142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.175474882 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:20.175518036 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.175606012 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:20.176069975 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:20.176089048 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.533412933 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.534024000 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:20.534048080 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.534343958 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.535669088 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:20.535732031 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:20.584918022 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:27.007524967 CEST4972480192.168.2.4199.232.210.172
                Apr 24, 2024 09:29:27.166953087 CEST8049724199.232.210.172192.168.2.4
                Apr 24, 2024 09:29:27.167037964 CEST8049724199.232.210.172192.168.2.4
                Apr 24, 2024 09:29:27.167184114 CEST4972480192.168.2.4199.232.210.172
                Apr 24, 2024 09:29:30.548450947 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:30.548660994 CEST44349754142.250.101.99192.168.2.4
                Apr 24, 2024 09:29:30.553906918 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:32.290086031 CEST49754443192.168.2.4142.250.101.99
                Apr 24, 2024 09:29:32.290122032 CEST44349754142.250.101.99192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                Apr 24, 2024 09:28:16.096471071 CEST53505981.1.1.1192.168.2.4
                Apr 24, 2024 09:28:16.143265009 CEST53614521.1.1.1192.168.2.4
                Apr 24, 2024 09:28:17.241409063 CEST53565051.1.1.1192.168.2.4
                Apr 24, 2024 09:28:17.470912933 CEST6213053192.168.2.41.1.1.1
                Apr 24, 2024 09:28:17.471113920 CEST5504453192.168.2.41.1.1.1
                Apr 24, 2024 09:28:17.663059950 CEST53621301.1.1.1192.168.2.4
                Apr 24, 2024 09:28:17.663211107 CEST53550441.1.1.1192.168.2.4
                Apr 24, 2024 09:28:19.421833038 CEST6430953192.168.2.41.1.1.1
                Apr 24, 2024 09:28:19.422564983 CEST5142053192.168.2.41.1.1.1
                Apr 24, 2024 09:28:19.576138973 CEST53514201.1.1.1192.168.2.4
                Apr 24, 2024 09:28:19.576184034 CEST53643091.1.1.1192.168.2.4
                Apr 24, 2024 09:28:20.143846035 CEST5360053192.168.2.41.1.1.1
                Apr 24, 2024 09:28:20.178606987 CEST6454053192.168.2.41.1.1.1
                Apr 24, 2024 09:28:20.297213078 CEST53536001.1.1.1192.168.2.4
                Apr 24, 2024 09:28:20.333169937 CEST53645401.1.1.1192.168.2.4
                Apr 24, 2024 09:28:21.597687960 CEST6411253192.168.2.41.1.1.1
                Apr 24, 2024 09:28:21.598042965 CEST5401753192.168.2.41.1.1.1
                Apr 24, 2024 09:28:21.751833916 CEST53540171.1.1.1192.168.2.4
                Apr 24, 2024 09:28:21.751884937 CEST53641121.1.1.1192.168.2.4
                Apr 24, 2024 09:28:35.287425995 CEST53610491.1.1.1192.168.2.4
                Apr 24, 2024 09:28:38.579816103 CEST138138192.168.2.4192.168.2.255
                Apr 24, 2024 09:28:54.172440052 CEST53531781.1.1.1192.168.2.4
                Apr 24, 2024 09:29:15.532834053 CEST53546701.1.1.1192.168.2.4
                Apr 24, 2024 09:29:17.225126982 CEST53639641.1.1.1192.168.2.4
                Apr 24, 2024 09:29:42.958928108 CEST53585981.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 24, 2024 09:28:17.470912933 CEST192.168.2.41.1.1.10xca26Standard query (0)app.firmway.inA (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:17.471113920 CEST192.168.2.41.1.1.10xdaf8Standard query (0)app.firmway.in65IN (0x0001)false
                Apr 24, 2024 09:28:19.421833038 CEST192.168.2.41.1.1.10xb921Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:19.422564983 CEST192.168.2.41.1.1.10x7c44Standard query (0)a.nel.cloudflare.com65IN (0x0001)false
                Apr 24, 2024 09:28:20.143846035 CEST192.168.2.41.1.1.10xe349Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.178606987 CEST192.168.2.41.1.1.10x93abStandard query (0)www.google.com65IN (0x0001)false
                Apr 24, 2024 09:28:21.597687960 CEST192.168.2.41.1.1.10x726cStandard query (0)app.firmway.inA (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:21.598042965 CEST192.168.2.41.1.1.10x6866Standard query (0)app.firmway.in65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 24, 2024 09:28:17.663059950 CEST1.1.1.1192.168.2.40xca26No error (0)app.firmway.in172.67.154.86A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:17.663059950 CEST1.1.1.1192.168.2.40xca26No error (0)app.firmway.in104.21.48.162A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:17.663211107 CEST1.1.1.1192.168.2.40xdaf8No error (0)app.firmway.in65IN (0x0001)false
                Apr 24, 2024 09:28:19.576184034 CEST1.1.1.1192.168.2.40xb921No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.99A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.147A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.105A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.106A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.104A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.297213078 CEST1.1.1.1192.168.2.40xe349No error (0)www.google.com142.250.101.103A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:20.333169937 CEST1.1.1.1192.168.2.40x93abNo error (0)www.google.com65IN (0x0001)false
                Apr 24, 2024 09:28:21.751833916 CEST1.1.1.1192.168.2.40x6866No error (0)app.firmway.in65IN (0x0001)false
                Apr 24, 2024 09:28:21.751884937 CEST1.1.1.1192.168.2.40x726cNo error (0)app.firmway.in104.21.48.162A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:21.751884937 CEST1.1.1.1192.168.2.40x726cNo error (0)app.firmway.in172.67.154.86A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:33.556406975 CEST1.1.1.1192.168.2.40x8c58No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Apr 24, 2024 09:28:33.556406975 CEST1.1.1.1192.168.2.40x8c58No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:34.658732891 CEST1.1.1.1192.168.2.40xd9d4No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 24, 2024 09:28:34.658732891 CEST1.1.1.1192.168.2.40xd9d4No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Apr 24, 2024 09:29:28.539210081 CEST1.1.1.1192.168.2.40xc220No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Apr 24, 2024 09:29:28.539210081 CEST1.1.1.1192.168.2.40xc220No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                • app.firmway.in
                • a.nel.cloudflare.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.449735172.67.154.86443764C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:18 UTC766OUTGET /confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email HTTP/1.1
                Host: app.firmway.in
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 07:28:19 UTC1351INHTTP/1.1 409 Conflict
                Date: Wed, 24 Apr 2024 07:28:19 GMT
                Content-Type: text/html; charset=UTF-8
                Transfer-Encoding: chunked
                Connection: close
                Cache-Control: no-cache, private
                X-RateLimit-Limit: 60
                X-RateLimit-Remaining: 59
                Content-Security-Policy: object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://salesiq.zoho.in/widget https://js.zohostatic.in https://js.zohocdn.com https://www.googletagmanager.com https://static.zohocdn.com https://js.zohocdn.com/ichat/js/2fc051ba_wmsbridge.js https://static.hotjar.com https://script.hotjar.com
                Permissions-Policy: accelerometer 'self'; ambient-light-sensor 'self'; autoplay 'self'; battery 'self'; camera 'self'; display-capture 'self'; document-domain *; encrypted-media 'self'; execution-while-not-rendered *; execution-while-out-of-viewport *; fullscreen 'self'; geolocation 'self'; gyroscope 'self'; layout-animations 'self'; legacy-image-formats 'self'; magnetometer 'self'; microphone 'self'; midi 'self'; navigation-override 'self'; oversized-images *; payment 'self'; picture-in-picture *; publickey-credentials 'self'; sync-xhr *; unoptimized-images 'self'; unsized-media *; usb 'self'; wake-lock 'self'; xr-spatial-tracking 'self'
                Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                X-Content-Type-Options: nosniff
                X-Download-Options: noopen
                2024-04-24 07:28:19 UTC1140INData Raw: 58 2d 46 72 61 6d 65 2d 4f 70 74 69 6f 6e 73 3a 20 73 61 6d 65 6f 72 69 67 69 6e 0d 0a 58 2d 50 65 72 6d 69 74 74 65 64 2d 43 72 6f 73 73 2d 44 6f 6d 61 69 6e 2d 50 6f 6c 69 63 69 65 73 3a 20 6e 6f 6e 65 0d 0a 58 2d 58 53 53 2d 50 72 6f 74 65 63 74 69 6f 6e 3a 20 31 3b 20 6d 6f 64 65 3d 62 6c 6f 63 6b 0d 0a 52 65 66 65 72 72 65 72 2d 50 6f 6c 69 63 79 3a 20 6e 6f 2d 72 65 66 65 72 72 65 72 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 58 53 52 46 2d 54 4f 4b 45 4e 3d 65 79 4a 70 64 69 49 36 49 6a 63 78 53 6a 64 55 54 33 6c 49 64 58 4e 35 62 44 6c 59 57 6b 46 54 55 47 49 31 51 31 45 39 50 53 49 73 49 6e 5a 68 62 48 56 6c 49 6a 6f 69 56 48 70 70 53 6a 64 61 62 48 41 35 62 6b 38 79 4e 7a 46 76 53 30 35 70 4e 31 64 58 62 57 70 43 52 53 74 51 61 44 4e 4a 54 44 52
                Data Ascii: X-Frame-Options: sameoriginX-Permitted-Cross-Domain-Policies: noneX-XSS-Protection: 1; mode=blockReferrer-Policy: no-referrerSet-Cookie: XSRF-TOKEN=eyJpdiI6IjcxSjdUT3lIdXN5bDlYWkFTUGI1Q1E9PSIsInZhbHVlIjoiVHppSjdabHA5bk8yNzFvS05pN1dXbWpCRStQaDNJTDR
                2024-04-24 07:28:19 UTC637INData Raw: 32 37 36 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 22 20 2f 3e 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 3e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 66 66 3b 20 63 6f 6c 6f 72 3a 20 23 32 32 32 3b 20 66 6f 6e 74 3a 20 31 36 70 78 2f 31 2e 35 20 2d 61 70 70 6c 65 2d 73 79 73 74 65 6d 2c 20 42 6c 69 6e 6b 4d 61 63 53 79 73 74 65 6d 46 6f 6e 74 2c 20
                Data Ascii: 276<!DOCTYPE html><html> <head> <meta charset="UTF-8" /> <meta name="robots" content="noindex,nofollow" /> <style> body { background-color: #fff; color: #222; font: 16px/1.5 -apple-system, BlinkMacSystemFont,
                2024-04-24 07:28:19 UTC5INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.449736172.67.154.86443764C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:20 UTC957OUTGET /favicon.ico HTTP/1.1
                Host: app.firmway.in
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: XSRF-TOKEN=eyJpdiI6IjcxSjdUT3lIdXN5bDlYWkFTUGI1Q1E9PSIsInZhbHVlIjoiVHppSjdabHA5bk8yNzFvS05pN1dXbWpCRStQaDNJTDRHVGozaXpHQ0Q0dm5DZlNPcEpzNjVZVURpbkMwTGxONVFzbFA4Q3hwQWpJczA2VHcra2ltV29NaUJSM0t1Vk1maE9EeWZwS1wvKzRpQWt0dzVzS1JKVmZzb2pwVVpOdHdBIiwibWFjIjoiMWUxOTc0ODZlZTAxNTkyYWIyZTMyYWMzZjViMjU4MDI0Y2U0NDZkNzI4ZmM5ZWI5ZGZhYWI5NGE1YWUyNGZhMiJ9; laravel_session=rBZXXukE7yMtqL1ef6T8u1XHldjRM4y2lQxkTvBE
                2024-04-24 07:28:21 UTC668INHTTP/1.1 200 OK
                Date: Wed, 24 Apr 2024 07:28:21 GMT
                Content-Type: image/x-icon
                Content-Length: 0
                Connection: close
                Last-Modified: Fri, 16 Jun 2023 14:36:09 GMT
                ETag: "648c7359-0"
                Cache-Control: max-age=120
                CF-Cache-Status: MISS
                Accept-Ranges: bytes
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BHmAeDIGFYA9R1d%2Ba%2Fk5ukBnmwh3myyxs3Cg8wYwdVRzRNZ3JxpCzQewiRKSeg6EZorL6KUV2S84J6Pjk4lfz4d2VDW8xDMnDPUKddhhwF6ObxT2i7cik90Qx2kHGMQqQQ%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 8794603d8ea60fd7-LAX
                alt-svc: h3=":443"; ma=86400


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.44973935.190.80.1443764C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:20 UTC545OUTOPTIONS /report/v4?s=xTsQDMLkVmb%2FlG7KG2bum3xecQ8Xhy9%2BsbKqS%2BzPIJceK2gkp1W71pHAFlzR6M2Jkewp6JIyHuwoW%2Boc7bk%2FIq4Oi6NwuwyH7k0K%2FOSfoMrrmRazC1YoyDaYiGNMaWhj%2BA%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Origin: https://app.firmway.in
                Access-Control-Request-Method: POST
                Access-Control-Request-Headers: content-type
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 07:28:20 UTC336INHTTP/1.1 200 OK
                Content-Length: 0
                access-control-max-age: 86400
                access-control-allow-methods: OPTIONS, POST
                access-control-allow-origin: *
                access-control-allow-headers: content-type, content-length
                date: Wed, 24 Apr 2024 07:28:19 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.44974035.190.80.1443764C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:20 UTC488OUTPOST /report/v4?s=xTsQDMLkVmb%2FlG7KG2bum3xecQ8Xhy9%2BsbKqS%2BzPIJceK2gkp1W71pHAFlzR6M2Jkewp6JIyHuwoW%2Boc7bk%2FIq4Oi6NwuwyH7k0K%2FOSfoMrrmRazC1YoyDaYiGNMaWhj%2BA%3D%3D HTTP/1.1
                Host: a.nel.cloudflare.com
                Connection: keep-alive
                Content-Length: 494
                Content-Type: application/reports+json
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-04-24 07:28:20 UTC494OUTData Raw: 5b 7b 22 61 67 65 22 3a 33 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 39 33 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 37 32 2e 36 37 2e 31 35 34 2e 38 36 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 39 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 61 70 70 2e 66 69 72 6d 77 61 79 2e 69 6e 2f
                Data Ascii: [{"age":3,"body":{"elapsed_time":1932,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"172.67.154.86","status_code":409,"type":"http.error"},"type":"network-error","url":"https://app.firmway.in/
                2024-04-24 07:28:21 UTC168INHTTP/1.1 200 OK
                Content-Length: 0
                date: Wed, 24 Apr 2024 07:28:20 GMT
                Via: 1.1 google
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.44974323.202.57.177443
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:21 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-24 07:28:21 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (sac/2518)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=257698
                Date: Wed, 24 Apr 2024 07:28:21 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.449744104.21.48.162443764C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:22 UTC756OUTGET /favicon.ico HTTP/1.1
                Host: app.firmway.in
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: */*
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: cors
                Sec-Fetch-Dest: empty
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: XSRF-TOKEN=eyJpdiI6IjcxSjdUT3lIdXN5bDlYWkFTUGI1Q1E9PSIsInZhbHVlIjoiVHppSjdabHA5bk8yNzFvS05pN1dXbWpCRStQaDNJTDRHVGozaXpHQ0Q0dm5DZlNPcEpzNjVZVURpbkMwTGxONVFzbFA4Q3hwQWpJczA2VHcra2ltV29NaUJSM0t1Vk1maE9EeWZwS1wvKzRpQWt0dzVzS1JKVmZzb2pwVVpOdHdBIiwibWFjIjoiMWUxOTc0ODZlZTAxNTkyYWIyZTMyYWMzZjViMjU4MDI0Y2U0NDZkNzI4ZmM5ZWI5ZGZhYWI5NGE1YWUyNGZhMiJ9; laravel_session=rBZXXukE7yMtqL1ef6T8u1XHldjRM4y2lQxkTvBE
                2024-04-24 07:28:22 UTC673INHTTP/1.1 200 OK
                Date: Wed, 24 Apr 2024 07:28:22 GMT
                Content-Type: image/x-icon
                Content-Length: 0
                Connection: close
                Last-Modified: Fri, 16 Jun 2023 14:36:09 GMT
                ETag: "648c7359-0"
                Cache-Control: max-age=120
                CF-Cache-Status: HIT
                Age: 1
                Accept-Ranges: bytes
                Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=llMzE5CWZ3aSbPeIRBtZMd3kzLLg4fxzdULDZYLb4yE1GShGMTPe0EcRRRGdrmro31cbyFqJk3TT0b6HpqZEf%2FRGRV0rzB4WLdlSmzdDaQNgCuzAssGcpOA3efzlbzI%2FRg%3D%3D"}],"group":"cf-nel","max_age":604800}
                NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                Server: cloudflare
                CF-RAY: 8794604bcb501005-LAX
                alt-svc: h3=":443"; ma=86400


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.44974523.202.57.177443
                TimestampBytes transferredDirectionData
                2024-04-24 07:28:22 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-04-24 07:28:22 UTC521INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-MSEdge-Ref: Ref A: CC1186E36C704BA5AF8177F229D6CC87 Ref B: PAOEDGE0621 Ref C: 2023-04-04T13:32:33Z
                Cache-Control: public, max-age=257649
                Date: Wed, 24 Apr 2024 07:28:22 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-04-24 07:28:22 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:09:28:11
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:09:28:14
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1940,i,8437511569128404353,3104943773025343623,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:09:28:16
                Start date:24/04/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.firmway.in/confirmation/reply?signed=%242y%2410%24Bt19gOrzcHoFrbxmjl0rE.a59%2FXSy4ybMib2ygo6Zw2AD%2FMM7T5WW&source=email"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly