Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org

Overview

General Information

Sample URL:https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org
Analysis ID:1431367
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6044 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1564 --field-trial-handle=2008,i,6480902847786206320,2322115140544708074,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6464 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.102.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org HTTP/1.1Host: click.em.isaca.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /expired.html HTTP/1.1Host: click.em.isaca.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: strict
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: click.em.isaca.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://click.em.isaca.org/expired.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: strict
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: click.em.isaca.org
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlDate: Wed, 24 Apr 2024 21:38:48 GMTConnection: closeContent-Length: 1245
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.102.27:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1564 --field-trial-handle=2008,i,6480902847786206320,2322115140544708074,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1564 --field-trial-handle=2008,i,6480902847786206320,2322115140544708074,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
click.em.isaca.org
13.111.235.232
truefalse
    high
    www.google.com
    142.250.141.103
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://click.em.isaca.org/favicon.icofalse
          high
          https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.orgfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            13.111.235.232
            click.em.isaca.orgUnited States
            22606EXACT-7USfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.141.103
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1431367
            Start date and time:2024-04-24 23:37:55 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 18s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/4@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.101, 142.251.2.102, 142.251.2.139, 142.251.2.138, 142.251.2.113, 142.251.2.100, 142.251.2.84, 34.104.35.123, 40.127.169.103, 72.21.81.240, 192.229.211.108, 13.85.23.206, 142.250.101.94
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
            Category:downloaded
            Size (bytes):269
            Entropy (8bit):5.135962333502038
            Encrypted:false
            SSDEEP:6:rzQ4Qn4mc4sLWAEtSVttXCWNUb/0M5Juvdt2WecuGMKicXfGu:r8P4WhkHhCS2/L5JuHlpPGu
            MD5:5CDCA02933085DEF753FDD5E3451E595
            SHA1:1438BE7B77514ADEBB48A18A4CCBB786AACBCDE6
            SHA-256:2BDA444D8888AF34681E93E72832BF8951B66F7B29E4F37F3B9A963B3991DCE2
            SHA-512:4FB8F9330D5705EAACD62009632C3880D603E5A318F9022341FCF4A37FFD7441900E3BDED8B3DE89F5C5EF01FFF5D9C308080E61367648CF0E6EB1D41690749B
            Malicious:false
            Reputation:low
            URL:https://click.em.isaca.org/expired.html
            Preview:.<!DOCTYPE html>..<html xmlns="http://www.w3.org/1999/xhtml">..<head>.. <meta name="ROBOTS" content="NOINDEX, NOFOLLOW">.. <title></title>..</head>..<body>..This link has expired. Please contact the sender of the email for more information...</body>..</html>..
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:downloaded
            Size (bytes):1245
            Entropy (8bit):5.462849750105637
            Encrypted:false
            SSDEEP:24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
            MD5:5343C1A8B203C162A3BF3870D9F50FD4
            SHA1:04B5B886C20D88B57EEA6D8FF882624A4AC1E51D
            SHA-256:DC1D54DAB6EC8C00F70137927504E4F222C8395F10760B6BEECFCFA94E08249F
            SHA-512:E0F50ACB6061744E825A4051765CEBF23E8C489B55B190739409D8A79BB08DAC8F919247A4E5F65A015EA9C57D326BBEF7EA045163915129E01F316C4958D949
            Malicious:false
            Reputation:low
            URL:https://click.em.isaca.org/favicon.ico
            Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>..<title>404 - File or directory not found.</title>..<style type="text/css">.. ..body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px 10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..background-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}..-->..</style>..</head>..<body>..<div id="header"><h1>Server Error</h1></div>..<div id="content">.. <div class="co
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 23:38:37.796569109 CEST49678443192.168.2.4104.46.162.224
            Apr 24, 2024 23:38:37.843461037 CEST49675443192.168.2.4173.222.162.32
            Apr 24, 2024 23:38:46.869429111 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.869512081 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:46.869776011 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.869810104 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.869856119 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:46.869910002 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.870038986 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.870106936 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:46.870269060 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:46.870280027 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.455595016 CEST49675443192.168.2.4173.222.162.32
            Apr 24, 2024 23:38:47.553375006 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.553781033 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.553844929 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.554944038 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.555079937 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.556948900 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.557063103 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.557437897 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.557497025 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.567725897 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.567972898 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.567996979 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.569495916 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.569571972 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.570323944 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.570401907 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.610650063 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.610663891 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.610668898 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.655602932 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.846180916 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.846265078 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.846342087 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.849040985 CEST49735443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.849083900 CEST4434973513.111.235.232192.168.2.4
            Apr 24, 2024 23:38:47.849944115 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:47.896131992 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.084709883 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.084841967 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.084903955 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.086138964 CEST49736443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.086159945 CEST4434973613.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.227628946 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.227675915 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.227762938 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.228039980 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.228049994 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.685731888 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.686680079 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.686698914 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.688208103 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.690004110 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.690428019 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.690429926 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:48.730061054 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:48.730078936 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:49.054151058 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.054199934 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.054265976 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.054486036 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.054503918 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.137053967 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:49.137229919 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:49.137295961 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:49.147562027 CEST49739443192.168.2.413.111.235.232
            Apr 24, 2024 23:38:49.147613049 CEST4434973913.111.235.232192.168.2.4
            Apr 24, 2024 23:38:49.414946079 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.416302919 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.416320086 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.417920113 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.417988062 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.654059887 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:49.654141903 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:49.654258966 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:49.657007933 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:49.657083988 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:49.673665047 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.673810005 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.717511892 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:49.717529058 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:49.764389992 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:50.014379978 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.014491081 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.022516012 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.022592068 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.022993088 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.077095032 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.130209923 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.176131964 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.344069004 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.344352961 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.344456911 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.344456911 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.344536066 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.344598055 CEST49742443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.344614983 CEST4434974223.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.381444931 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.381509066 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.381570101 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.382100105 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.382121086 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.730916023 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.730990887 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.732238054 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.732250929 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.733297110 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:50.734406948 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:50.776156902 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:51.070858955 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:51.071039915 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:51.071178913 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:51.071775913 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:51.071799040 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:51.071810961 CEST49743443192.168.2.423.1.102.27
            Apr 24, 2024 23:38:51.071819067 CEST4434974323.1.102.27192.168.2.4
            Apr 24, 2024 23:38:59.418534994 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:59.418591022 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:38:59.418673038 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:59.476437092 CEST49740443192.168.2.4142.250.141.103
            Apr 24, 2024 23:38:59.476459026 CEST44349740142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:48.939743996 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:48.939801931 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:48.939874887 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:48.940140963 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:48.940160036 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:49.298868895 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:49.299665928 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:49.299684048 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:49.300169945 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:49.301090002 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:49.301175117 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:49.342403889 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:59.308423996 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:59.308638096 CEST44349752142.250.141.103192.168.2.4
            Apr 24, 2024 23:39:59.308752060 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:59.523155928 CEST49752443192.168.2.4142.250.141.103
            Apr 24, 2024 23:39:59.523186922 CEST44349752142.250.141.103192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 24, 2024 23:38:45.173885107 CEST53585171.1.1.1192.168.2.4
            Apr 24, 2024 23:38:45.180272102 CEST53568671.1.1.1192.168.2.4
            Apr 24, 2024 23:38:46.134504080 CEST53624981.1.1.1192.168.2.4
            Apr 24, 2024 23:38:46.613946915 CEST6507453192.168.2.41.1.1.1
            Apr 24, 2024 23:38:46.614118099 CEST5964853192.168.2.41.1.1.1
            Apr 24, 2024 23:38:46.868417978 CEST53650741.1.1.1192.168.2.4
            Apr 24, 2024 23:38:46.868602037 CEST53596481.1.1.1192.168.2.4
            Apr 24, 2024 23:38:48.895209074 CEST6000353192.168.2.41.1.1.1
            Apr 24, 2024 23:38:48.895454884 CEST5824053192.168.2.41.1.1.1
            Apr 24, 2024 23:38:49.048585892 CEST53582401.1.1.1192.168.2.4
            Apr 24, 2024 23:38:49.049101114 CEST53600031.1.1.1192.168.2.4
            Apr 24, 2024 23:39:04.466957092 CEST53584211.1.1.1192.168.2.4
            Apr 24, 2024 23:39:08.353138924 CEST138138192.168.2.4192.168.2.255
            Apr 24, 2024 23:39:23.274718046 CEST53573551.1.1.1192.168.2.4
            Apr 24, 2024 23:39:44.460431099 CEST53556831.1.1.1192.168.2.4
            Apr 24, 2024 23:39:45.579346895 CEST53613041.1.1.1192.168.2.4
            Apr 24, 2024 23:40:12.748215914 CEST53572651.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 24, 2024 23:38:46.613946915 CEST192.168.2.41.1.1.10x4f9dStandard query (0)click.em.isaca.orgA (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:46.614118099 CEST192.168.2.41.1.1.10x2868Standard query (0)click.em.isaca.org65IN (0x0001)false
            Apr 24, 2024 23:38:48.895209074 CEST192.168.2.41.1.1.10xc69bStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:48.895454884 CEST192.168.2.41.1.1.10x1bb0Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 24, 2024 23:38:46.868417978 CEST1.1.1.1192.168.2.40x4f9dNo error (0)click.em.isaca.org13.111.235.232A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.048585892 CEST1.1.1.1192.168.2.40x1bb0No error (0)www.google.com65IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.103A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.104A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.99A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.106A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.147A (IP address)IN (0x0001)false
            Apr 24, 2024 23:38:49.049101114 CEST1.1.1.1192.168.2.40xc69bNo error (0)www.google.com142.250.141.105A (IP address)IN (0x0001)false
            Apr 24, 2024 23:39:02.405284882 CEST1.1.1.1192.168.2.40xcc74No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 23:39:02.405284882 CEST1.1.1.1192.168.2.40xcc74No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 23:39:15.739159107 CEST1.1.1.1192.168.2.40xa6bbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 23:39:15.739159107 CEST1.1.1.1192.168.2.40xa6bbNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 23:39:38.356865883 CEST1.1.1.1192.168.2.40x6518No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 23:39:38.356865883 CEST1.1.1.1192.168.2.40x6518No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            Apr 24, 2024 23:39:57.467470884 CEST1.1.1.1192.168.2.40x4b9cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 24, 2024 23:39:57.467470884 CEST1.1.1.1192.168.2.40x4b9cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
            • click.em.isaca.org
            • https:
            • fs.microsoft.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.44973513.111.235.2324436044C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-24 21:38:47 UTC814OUTGET /?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org HTTP/1.1
            Host: click.em.isaca.org
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2024-04-24 21:38:47 UTC582INHTTP/1.1 302 Found
            Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
            Content-Type: text/html; charset=utf-8
            Location: /expired.html
            Content-Security-Policy: default-src 'self'; frame-ancestors 'self'
            X-Frame-Options: SAMEORIGIN
            X-Content-Type-Options: nosniff
            Referrer-Policy: origin-when-cross-origin
            Strict-Transport-Security: max-age=31536000; includeSubDomains
            X-XSS-Protection: 1; mode=block
            Permissions-Policy: geolocation=(self), microphone=()
            Set-Cookie: strict
            Date: Wed, 24 Apr 2024 21:38:46 GMT
            Connection: close
            Content-Length: 130
            2024-04-24 21:38:47 UTC130INData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 32 3e 4f 62 6a 65 63 74 20 6d 6f 76 65 64 20 74 6f 20 3c 61 20 68 72 65 66 3d 22 2f 65 78 70 69 72 65 64 2e 68 74 6d 6c 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 68 32 3e 0d 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: <html><head><title>Object moved</title></head><body><h2>Object moved to <a href="/expired.html">here</a>.</h2></body></html>


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.44973613.111.235.2324436044C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-24 21:38:47 UTC689OUTGET /expired.html HTTP/1.1
            Host: click.em.isaca.org
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: strict
            2024-04-24 21:38:48 UTC215INHTTP/1.1 200 OK
            Content-Type: text/html
            Last-Modified: Tue, 16 Apr 2024 09:42:44 GMT
            Accept-Ranges: bytes
            ETag: "0427e6ee28fda1:0"
            Date: Wed, 24 Apr 2024 21:38:47 GMT
            Connection: close
            Content-Length: 269
            2024-04-24 21:38:48 UTC269INData Raw: ef bb bf 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 52 4f 42 4f 54 53 22 20 63 6f 6e 74 65 6e 74 3d 22 4e 4f 49 4e 44 45 58 2c 20 4e 4f 46 4f 4c 4c 4f 57 22 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 54 68 69 73 20 6c 69 6e 6b 20 68 61 73 20 65 78 70 69 72 65 64 2e 20 20 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 6e 64 65 72 20 6f 66 20 74 68 65 20 65 6d 61 69 6c 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0d 0a 3c 2f 62 6f
            Data Ascii: <!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml"><head> <meta name="ROBOTS" content="NOINDEX, NOFOLLOW"> <title></title></head><body>This link has expired. Please contact the sender of the email for more information.</bo


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.44973913.111.235.2324436044C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2024-04-24 21:38:48 UTC620OUTGET /favicon.ico HTTP/1.1
            Host: click.em.isaca.org
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://click.em.isaca.org/expired.html
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            Cookie: strict
            2024-04-24 21:38:49 UTC129INHTTP/1.1 404 Not Found
            Content-Type: text/html
            Date: Wed, 24 Apr 2024 21:38:48 GMT
            Connection: close
            Content-Length: 1245
            2024-04-24 21:38:49 UTC1109INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c
            Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/><title>404 - Fil
            2024-04-24 21:38:49 UTC136INData Raw: 67 20 66 6f 72 20 6d 69 67 68 74 20 68 61 76 65 20 62 65 65 6e 20 72 65 6d 6f 76 65 64 2c 20 68 61 64 20 69 74 73 20 6e 61 6d 65 20 63 68 61 6e 67 65 64 2c 20 6f 72 20 69 73 20 74 65 6d 70 6f 72 61 72 69 6c 79 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 2f 68 33 3e 0d 0a 20 3c 2f 66 69 65 6c 64 73 65 74 3e 3c 2f 64 69 76 3e 0d 0a 3c 2f 64 69 76 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
            Data Ascii: g for might have been removed, had its name changed, or is temporarily unavailable.</h3> </fieldset></div></div></body></html>


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.44974223.1.102.27443
            TimestampBytes transferredDirectionData
            2024-04-24 21:38:50 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-24 21:38:50 UTC467INHTTP/1.1 200 OK
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            Content-Type: application/octet-stream
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            Server: ECAcc (sac/2518)
            X-CID: 11
            X-Ms-ApiVersion: Distribute 1.2
            X-Ms-Region: prod-eus-z1
            Cache-Control: public, max-age=206645
            Date: Wed, 24 Apr 2024 21:38:50 GMT
            Connection: close
            X-CID: 2


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.44974323.1.102.27443
            TimestampBytes transferredDirectionData
            2024-04-24 21:38:50 UTC239OUTGET /fs/windows/config.json HTTP/1.1
            Connection: Keep-Alive
            Accept: */*
            Accept-Encoding: identity
            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
            Range: bytes=0-2147483646
            User-Agent: Microsoft BITS/7.8
            Host: fs.microsoft.com
            2024-04-24 21:38:51 UTC531INHTTP/1.1 200 OK
            Content-Type: application/octet-stream
            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
            ApiVersion: Distribute 1.1
            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
            X-Azure-Ref: 0Fz4RYwAAAACZW8dCTzveR7lI76J6Z2l5U0pDRURHRTA1MTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
            Cache-Control: public, max-age=206690
            Date: Wed, 24 Apr 2024 21:38:50 GMT
            Content-Length: 55
            Connection: close
            X-CID: 2
            2024-04-24 21:38:51 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:23:38:40
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:23:38:42
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1564 --field-trial-handle=2008,i,6480902847786206320,2322115140544708074,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:23:38:45
            Start date:24/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.em.isaca.org/?qs=aa3355078a4695cbcba800baec076fd3fd3eab8fe3d9e77bd79d3f87be73b1fe49da28824df5c6a4b08e10e6c870ef9665c68b01d55d20e32cc014cc97c0d9e5%20click.em.isaca.org"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly