Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://2h.ae/HWtB

Overview

General Information

Sample URL:https://2h.ae/HWtB
Analysis ID:1431057
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 5552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,7220497278789268327,86842902818398423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://2h.ae/HWtB" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://2h.ae/HWtBAvira URL Cloud: detection malicious, Label: phishing
Source: https://dgt.lat/entraHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 23.206.6.29
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /HWtB HTTP/1.1Host: 2h.aeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /entra HTTP/1.1Host: dgt.latConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dgt.latConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dgt.lat/entraAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: 2h.ae
Source: global trafficDNS traffic detected: DNS query: dgt.lat
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownHTTP traffic detected: POST /report/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 383Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 24 Apr 2024 12:20:51 GMTContent-Type: text/plain; charset=utf-8Content-Length: 9Connection: closeAccess-Control-Allow-Origin: *ETag: W/"9-0gXL1ngzMqISxa6S1zx3F4wtLyg"CF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 87960cba6934100b-LAXalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 24 Apr 2024 12:20:51 GMTContent-Type: text/plain; charset=utf-8Content-Length: 9Connection: closeAccess-Control-Allow-Origin: *ETag: W/"9-0gXL1ngzMqISxa6S1zx3F4wtLyg"Cache-Control: max-age=14400CF-Cache-Status: MISSReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2q"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 87960cc09b3c7e80-LAXalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.206.6.29:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: mal48.win@17/4@8/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,7220497278789268327,86842902818398423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://2h.ae/HWtB"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,7220497278789268327,86842902818398423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://2h.ae/HWtB100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://dgt.lat/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
a.nel.cloudflare.com
35.190.80.1
truefalse
    high
    dgt.lat
    104.21.56.244
    truefalse
      unknown
      www.google.com
      142.250.141.104
      truefalse
        high
        2h.ae
        172.67.205.158
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://dgt.lat/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://a.nel.cloudflare.com/report/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2qfalse
              high
              https://2h.ae/HWtBtrue
                unknown
                https://a.nel.cloudflare.com/report/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrWfalse
                  high
                  https://dgt.lat/entrafalse
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    104.21.56.244
                    dgt.latUnited States
                    13335CLOUDFLARENETUSfalse
                    35.190.80.1
                    a.nel.cloudflare.comUnited States
                    15169GOOGLEUSfalse
                    142.250.141.104
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    172.67.205.158
                    2h.aeUnited States
                    13335CLOUDFLARENETUSfalse
                    IP
                    192.168.2.4
                    192.168.2.5
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1431057
                    Start date and time:2024-04-24 14:19:55 +02:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 8s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://2h.ae/HWtB
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal48.win@17/4@8/7
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.139, 142.251.2.100, 142.251.2.138, 142.251.2.102, 142.251.2.101, 142.251.2.113, 142.251.2.84, 34.104.35.123, 20.12.23.50, 23.1.234.57, 23.1.234.24, 192.229.211.108, 20.3.187.198, 142.250.101.94
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with no line terminators
                    Category:downloaded
                    Size (bytes):9
                    Entropy (8bit):2.94770277922009
                    Encrypted:false
                    SSDEEP:3:Obn:Obn
                    MD5:9D1EAD73E678FA2F51A70A933B0BF017
                    SHA1:D205CBD6783332A212C5AE92D73C77178C2D2F28
                    SHA-256:0019DFC4B32D63C1392AA264AED2253C1E0C2FB09216F8E2CC269BBFB8BB49B5
                    SHA-512:935B3D516E996F6D25948BA8A54C1B7F70F7F0E3F517E36481FDF0196C2C5CFC2841F86E891F3DF9517746B7FB605DB47CDDED1B8FF78D9482DDAA621DB43A34
                    Malicious:false
                    Reputation:low
                    URL:https://dgt.lat/favicon.ico
                    Preview:Not Found
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:ASCII text, with no line terminators
                    Category:downloaded
                    Size (bytes):9
                    Entropy (8bit):2.94770277922009
                    Encrypted:false
                    SSDEEP:3:Obn:Obn
                    MD5:9D1EAD73E678FA2F51A70A933B0BF017
                    SHA1:D205CBD6783332A212C5AE92D73C77178C2D2F28
                    SHA-256:0019DFC4B32D63C1392AA264AED2253C1E0C2FB09216F8E2CC269BBFB8BB49B5
                    SHA-512:935B3D516E996F6D25948BA8A54C1B7F70F7F0E3F517E36481FDF0196C2C5CFC2841F86E891F3DF9517746B7FB605DB47CDDED1B8FF78D9482DDAA621DB43A34
                    Malicious:false
                    Reputation:low
                    URL:https://dgt.lat/entra
                    Preview:Not Found
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 24, 2024 14:20:38.383193970 CEST49678443192.168.2.4104.46.162.224
                    Apr 24, 2024 14:20:40.507972002 CEST49675443192.168.2.4173.222.162.32
                    Apr 24, 2024 14:20:48.277358055 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.277439117 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.277587891 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.277822018 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.277883053 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.277932882 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.278089046 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.278140068 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.278234005 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.278253078 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.611964941 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.612293959 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.612313032 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.613363028 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.613430023 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.614033937 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.614691973 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.614712954 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.615724087 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.615791082 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.615984917 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.615993977 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.616229057 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.616290092 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.617373943 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.617458105 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.660655975 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.661391020 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:48.661426067 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:48.709235907 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:49.973352909 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:49.977591038 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:49.977634907 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:49.981472015 CEST49737443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:20:49.981499910 CEST44349737172.67.205.158192.168.2.4
                    Apr 24, 2024 14:20:50.119702101 CEST49675443192.168.2.4173.222.162.32
                    Apr 24, 2024 14:20:50.239497900 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.239550114 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.239629030 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.240295887 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.240325928 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.355494022 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.355576038 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.355658054 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.355887890 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.355921030 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.573556900 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.577461004 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.577497959 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.579093933 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.579179049 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.716877937 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.717217922 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.717272997 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.718251944 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.718359947 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.801234961 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:50.801278114 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:50.801522017 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:50.810359001 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:50.810373068 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:50.865324974 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.865324974 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.865408897 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.865565062 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.866050005 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.866218090 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.914963007 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:50.914982080 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.914992094 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:20:50.915039062 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:50.959391117 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:50.959471941 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:20:51.155462027 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.155822992 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.161392927 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.161437035 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.161664963 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.205389023 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.212076902 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.212239981 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.214816093 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.223974943 CEST49739443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.223999977 CEST44349739104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.320127964 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.320194006 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.321443081 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.321789026 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.321825981 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.356055975 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.391154051 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.391208887 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.391371012 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.393471003 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.393488884 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.396152973 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.525125980 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.525187016 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.525247097 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.547581911 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.547646046 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.547677994 CEST49741443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.547694921 CEST4434974123.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.606946945 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.606990099 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.607058048 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.607908964 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.607925892 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.656213999 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.656558990 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.656582117 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.657741070 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.658648968 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.658844948 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.659091949 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:51.700145006 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:51.755716085 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.756336927 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.756350040 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.757921934 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.757987022 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.766952038 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.767041922 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.767173052 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.767187119 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:51.819247961 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:51.954957008 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.955053091 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.956397057 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:51.956423998 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.957412004 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:51.958764076 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:52.004112959 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:52.041649103 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:52.041733027 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:52.041795015 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:52.042531967 CEST49742443192.168.2.4104.21.56.244
                    Apr 24, 2024 14:20:52.042576075 CEST44349742104.21.56.244192.168.2.4
                    Apr 24, 2024 14:20:52.136362076 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.136431932 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.136473894 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.136625051 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.136651039 CEST4434974335.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.136662960 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.136701107 CEST49743443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.137089014 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.137124062 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.137190104 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.137443066 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.137458086 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.316171885 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:52.316338062 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:52.316402912 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:52.321405888 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:52.321460009 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:52.321501017 CEST49744443192.168.2.423.206.6.29
                    Apr 24, 2024 14:20:52.321517944 CEST4434974423.206.6.29192.168.2.4
                    Apr 24, 2024 14:20:52.487298012 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.505477905 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.505502939 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.506704092 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.553986073 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.587009907 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.587179899 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.588035107 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.628151894 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.877614975 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.877707005 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:20:52.877854109 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.889785051 CEST49745443192.168.2.435.190.80.1
                    Apr 24, 2024 14:20:52.889837027 CEST4434974535.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:00.716429949 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:00.716495037 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:00.716801882 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:02.498891115 CEST49740443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:02.498960018 CEST44349740142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:03.599906921 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:21:03.599976063 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:21:03.600044012 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:21:04.248971939 CEST49736443192.168.2.4172.67.205.158
                    Apr 24, 2024 14:21:04.249032021 CEST44349736172.67.205.158192.168.2.4
                    Apr 24, 2024 14:21:50.228914976 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:50.228949070 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.229022026 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:50.230024099 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:50.230036974 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.589513063 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.590188026 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:50.590214968 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.591310024 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.591983080 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:50.592067003 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:21:50.646783113 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:21:51.226382971 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.226466894 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.226553917 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.227974892 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.228012085 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.576412916 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.576740980 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.576806068 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.577933073 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.578478098 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.578641891 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.578675032 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.631186008 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.972615004 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.972815990 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.972879887 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.973306894 CEST49756443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.973315954 CEST4434975635.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.974731922 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.974744081 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:51.974809885 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.975469112 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:51.975482941 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.327585936 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.331432104 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.331444979 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.331914902 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.346462011 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.346666098 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.355849028 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.396141052 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.719677925 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.719875097 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.719943047 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.720109940 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.720118999 CEST4434975735.190.80.1192.168.2.4
                    Apr 24, 2024 14:21:52.720168114 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:52.720176935 CEST49757443192.168.2.435.190.80.1
                    Apr 24, 2024 14:21:57.321047068 CEST4972380192.168.2.472.21.81.240
                    Apr 24, 2024 14:21:57.321341991 CEST4972480192.168.2.472.21.81.240
                    Apr 24, 2024 14:21:57.480293989 CEST804972372.21.81.240192.168.2.4
                    Apr 24, 2024 14:21:57.480475903 CEST4972380192.168.2.472.21.81.240
                    Apr 24, 2024 14:21:57.480567932 CEST804972472.21.81.240192.168.2.4
                    Apr 24, 2024 14:21:57.480762959 CEST4972480192.168.2.472.21.81.240
                    Apr 24, 2024 14:22:00.597408056 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:22:00.597588062 CEST44349755142.250.141.104192.168.2.4
                    Apr 24, 2024 14:22:00.597681999 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:22:02.244451046 CEST49755443192.168.2.4142.250.141.104
                    Apr 24, 2024 14:22:02.244483948 CEST44349755142.250.141.104192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 24, 2024 14:20:46.165534019 CEST53642821.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:46.172344923 CEST53565781.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:47.268094063 CEST53558601.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:48.103518963 CEST5116153192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:48.103641033 CEST5842553192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:48.275902033 CEST53511611.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:48.276595116 CEST53584251.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:49.984749079 CEST5694153192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:49.985346079 CEST5993253192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:50.177879095 CEST5572853192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:50.200762987 CEST5066153192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:50.223027945 CEST53599321.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:50.223076105 CEST53569411.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:50.331564903 CEST53557281.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:50.354425907 CEST53506611.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:51.221642017 CEST4986853192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:51.221642971 CEST5115953192.168.2.41.1.1.1
                    Apr 24, 2024 14:20:51.377803087 CEST53498681.1.1.1192.168.2.4
                    Apr 24, 2024 14:20:51.390379906 CEST53511591.1.1.1192.168.2.4
                    Apr 24, 2024 14:21:04.646287918 CEST53582691.1.1.1192.168.2.4
                    Apr 24, 2024 14:21:08.908278942 CEST138138192.168.2.4192.168.2.255
                    Apr 24, 2024 14:21:23.695956945 CEST53523401.1.1.1192.168.2.4
                    Apr 24, 2024 14:21:45.726653099 CEST53562501.1.1.1192.168.2.4
                    Apr 24, 2024 14:21:46.719619989 CEST53561471.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Apr 24, 2024 14:20:48.103518963 CEST192.168.2.41.1.1.10x6d89Standard query (0)2h.aeA (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:48.103641033 CEST192.168.2.41.1.1.10xbd7Standard query (0)2h.ae65IN (0x0001)false
                    Apr 24, 2024 14:20:49.984749079 CEST192.168.2.41.1.1.10xb89fStandard query (0)dgt.latA (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:49.985346079 CEST192.168.2.41.1.1.10x9fcbStandard query (0)dgt.lat65IN (0x0001)false
                    Apr 24, 2024 14:20:50.177879095 CEST192.168.2.41.1.1.10x6402Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.200762987 CEST192.168.2.41.1.1.10xff6fStandard query (0)www.google.com65IN (0x0001)false
                    Apr 24, 2024 14:20:51.221642017 CEST192.168.2.41.1.1.10x34b2Standard query (0)a.nel.cloudflare.comA (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:51.221642971 CEST192.168.2.41.1.1.10x8d9fStandard query (0)a.nel.cloudflare.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Apr 24, 2024 14:20:48.275902033 CEST1.1.1.1192.168.2.40x6d89No error (0)2h.ae172.67.205.158A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:48.275902033 CEST1.1.1.1192.168.2.40x6d89No error (0)2h.ae104.21.77.80A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:48.276595116 CEST1.1.1.1192.168.2.40xbd7No error (0)2h.ae65IN (0x0001)false
                    Apr 24, 2024 14:20:50.223027945 CEST1.1.1.1192.168.2.40x9fcbNo error (0)dgt.lat65IN (0x0001)false
                    Apr 24, 2024 14:20:50.223076105 CEST1.1.1.1192.168.2.40xb89fNo error (0)dgt.lat104.21.56.244A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.223076105 CEST1.1.1.1192.168.2.40xb89fNo error (0)dgt.lat172.67.138.233A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.331564903 CEST1.1.1.1192.168.2.40x6402No error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:20:50.354425907 CEST1.1.1.1192.168.2.40xff6fNo error (0)www.google.com65IN (0x0001)false
                    Apr 24, 2024 14:20:51.377803087 CEST1.1.1.1192.168.2.40x34b2No error (0)a.nel.cloudflare.com35.190.80.1A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:21:03.813492060 CEST1.1.1.1192.168.2.40xa092No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 24, 2024 14:21:03.813492060 CEST1.1.1.1192.168.2.40xa092No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:21:16.780989885 CEST1.1.1.1192.168.2.40x4babNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 24, 2024 14:21:16.780989885 CEST1.1.1.1192.168.2.40x4babNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:21:38.739985943 CEST1.1.1.1192.168.2.40x801dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 24, 2024 14:21:38.739985943 CEST1.1.1.1192.168.2.40x801dNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Apr 24, 2024 14:21:58.943013906 CEST1.1.1.1192.168.2.40x9c96No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Apr 24, 2024 14:21:58.943013906 CEST1.1.1.1192.168.2.40x9c96No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • 2h.ae
                    • dgt.lat
                    • https:
                    • fs.microsoft.com
                    • a.nel.cloudflare.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449737172.67.205.1584432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:48 UTC652OUTGET /HWtB HTTP/1.1
                    Host: 2h.ae
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:20:49 UTC926INHTTP/1.1 301 Moved Permanently
                    Date: Wed, 24 Apr 2024 12:20:49 GMT
                    Content-Type: text/html; charset=UTF-8
                    Transfer-Encoding: chunked
                    Connection: close
                    X-Powered-By: PHP/7.4.30
                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                    Cache-Control: no-store, no-cache, must-revalidate
                    Pragma: no-cache
                    Set-Cookie: PHPSESSID=g3a6kt5fafktbdmla3g03j5sjo; path=/
                    Set-Cookie: short_179918=1; expires=Wed, 24-Apr-2024 12:32:04 GMT; Max-Age=900; path=/; HttpOnly
                    location: https://dgt.lat/entra
                    Vary: User-Agent
                    CF-Cache-Status: DYNAMIC
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Q8T%2BqrWfmsds8D8ZZlu6e3BsNqQUWK9rcQ6PjMPuu%2BeplD%2BDgr2lh%2B4zfW8SbzQo27h550WKXGI6VThNK0wH98AJjbMgGe3r3%2BV8V1PQaZHJuovAygG11w%3D%3D"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 87960cad8a1c1035-LAX
                    alt-svc: h3=":443"; ma=86400
                    2024-04-24 12:20:49 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449739104.21.56.2444432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:50 UTC655OUTGET /entra HTTP/1.1
                    Host: dgt.lat
                    Connection: keep-alive
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:20:51 UTC632INHTTP/1.1 404 Not Found
                    Date: Wed, 24 Apr 2024 12:20:51 GMT
                    Content-Type: text/plain; charset=utf-8
                    Content-Length: 9
                    Connection: close
                    Access-Control-Allow-Origin: *
                    ETag: W/"9-0gXL1ngzMqISxa6S1zx3F4wtLyg"
                    CF-Cache-Status: DYNAMIC
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 87960cba6934100b-LAX
                    alt-svc: h3=":443"; ma=86400
                    2024-04-24 12:20:51 UTC9INData Raw: 4e 6f 74 20 46 6f 75 6e 64
                    Data Ascii: Not Found


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.44974123.206.6.29443
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:51 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-24 12:20:51 UTC467INHTTP/1.1 200 OK
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (sac/2518)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus-z1
                    Cache-Control: public, max-age=240177
                    Date: Wed, 24 Apr 2024 12:20:51 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.449742104.21.56.2444432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:51 UTC575OUTGET /favicon.ico HTTP/1.1
                    Host: dgt.lat
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    sec-ch-ua-platform: "Windows"
                    Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                    Sec-Fetch-Site: same-origin
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: image
                    Referer: https://dgt.lat/entra
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:20:52 UTC657INHTTP/1.1 404 Not Found
                    Date: Wed, 24 Apr 2024 12:20:51 GMT
                    Content-Type: text/plain; charset=utf-8
                    Content-Length: 9
                    Connection: close
                    Access-Control-Allow-Origin: *
                    ETag: W/"9-0gXL1ngzMqISxa6S1zx3F4wtLyg"
                    Cache-Control: max-age=14400
                    CF-Cache-Status: MISS
                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2q"}],"group":"cf-nel","max_age":604800}
                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                    Server: cloudflare
                    CF-RAY: 87960cc09b3c7e80-LAX
                    alt-svc: h3=":443"; ma=86400
                    2024-04-24 12:20:52 UTC9INData Raw: 4e 6f 74 20 46 6f 75 6e 64
                    Data Ascii: Not Found


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.44974335.190.80.14432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:51 UTC514OUTOPTIONS /report/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Origin: https://dgt.lat
                    Access-Control-Request-Method: POST
                    Access-Control-Request-Headers: content-type
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:20:52 UTC336INHTTP/1.1 200 OK
                    Content-Length: 0
                    access-control-max-age: 86400
                    access-control-allow-methods: POST, OPTIONS
                    access-control-allow-origin: *
                    access-control-allow-headers: content-length, content-type
                    date: Wed, 24 Apr 2024 12:20:51 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    5192.168.2.44974423.206.6.29443
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:51 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-04-24 12:20:52 UTC531INHTTP/1.1 200 OK
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Content-Type: application/octet-stream
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-Azure-Ref: 0Fz4RYwAAAACZW8dCTzveR7lI76J6Z2l5U0pDRURHRTA1MTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=240169
                    Date: Wed, 24 Apr 2024 12:20:52 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-04-24 12:20:52 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    6192.168.2.44974535.190.80.14432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:20:52 UTC464OUTPOST /report/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Content-Length: 383
                    Content-Type: application/reports+json
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:20:52 UTC383OUTData Raw: 5b 7b 22 61 67 65 22 3a 30 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 31 32 33 36 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 35 36 2e 32 34 34 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 64 67 74 2e 6c 61 74 2f 65 6e 74 72 61 22 2c
                    Data Ascii: [{"age":0,"body":{"elapsed_time":1236,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"","sampling_fraction":1.0,"server_ip":"104.21.56.244","status_code":404,"type":"http.error"},"type":"network-error","url":"https://dgt.lat/entra",
                    2024-04-24 12:20:52 UTC168INHTTP/1.1 200 OK
                    Content-Length: 0
                    date: Wed, 24 Apr 2024 12:20:52 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    7192.168.2.44975635.190.80.14432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:21:51 UTC512OUTOPTIONS /report/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2q HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Origin: https://dgt.lat
                    Access-Control-Request-Method: POST
                    Access-Control-Request-Headers: content-type
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:21:51 UTC336INHTTP/1.1 200 OK
                    Content-Length: 0
                    access-control-max-age: 86400
                    access-control-allow-methods: POST, OPTIONS
                    access-control-allow-origin: *
                    access-control-allow-headers: content-type, content-length
                    date: Wed, 24 Apr 2024 12:21:51 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    8192.168.2.44975735.190.80.14432840C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-04-24 12:21:52 UTC462OUTPOST /report/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2q HTTP/1.1
                    Host: a.nel.cloudflare.com
                    Connection: keep-alive
                    Content-Length: 413
                    Content-Type: application/reports+json
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-04-24 12:21:52 UTC413OUTData Raw: 5b 7b 22 61 67 65 22 3a 35 39 31 38 33 2c 22 62 6f 64 79 22 3a 7b 22 65 6c 61 70 73 65 64 5f 74 69 6d 65 22 3a 37 32 32 2c 22 6d 65 74 68 6f 64 22 3a 22 47 45 54 22 2c 22 70 68 61 73 65 22 3a 22 61 70 70 6c 69 63 61 74 69 6f 6e 22 2c 22 70 72 6f 74 6f 63 6f 6c 22 3a 22 68 74 74 70 2f 31 2e 31 22 2c 22 72 65 66 65 72 72 65 72 22 3a 22 68 74 74 70 73 3a 2f 2f 64 67 74 2e 6c 61 74 2f 65 6e 74 72 61 22 2c 22 73 61 6d 70 6c 69 6e 67 5f 66 72 61 63 74 69 6f 6e 22 3a 31 2e 30 2c 22 73 65 72 76 65 72 5f 69 70 22 3a 22 31 30 34 2e 32 31 2e 35 36 2e 32 34 34 22 2c 22 73 74 61 74 75 73 5f 63 6f 64 65 22 3a 34 30 34 2c 22 74 79 70 65 22 3a 22 68 74 74 70 2e 65 72 72 6f 72 22 7d 2c 22 74 79 70 65 22 3a 22 6e 65 74 77 6f 72 6b 2d 65 72 72 6f 72 22 2c 22 75 72 6c 22 3a
                    Data Ascii: [{"age":59183,"body":{"elapsed_time":722,"method":"GET","phase":"application","protocol":"http/1.1","referrer":"https://dgt.lat/entra","sampling_fraction":1.0,"server_ip":"104.21.56.244","status_code":404,"type":"http.error"},"type":"network-error","url":
                    2024-04-24 12:21:52 UTC168INHTTP/1.1 200 OK
                    Content-Length: 0
                    date: Wed, 24 Apr 2024 12:21:52 GMT
                    Via: 1.1 google
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:14:20:41
                    Start date:24/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:14:20:44
                    Start date:24/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,7220497278789268327,86842902818398423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:14:20:47
                    Start date:24/04/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://2h.ae/HWtB"
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly