Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ

Overview

General Information

Sample URL:https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ
Analysis ID:1431881
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1852 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1828 --field-trial-handle=1956,i,3247001600556690069,7833688900923320994,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6480 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 69.164.42.0
Source: unknownTCP traffic detected without corresponding DNS query: 69.164.42.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.204.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.204.82
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.dropbox.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: gvc=MTY3ODcwNDExMzE1Nzk0Mjc4NTA0NjQ4MTk5MDE3ODY4NDMwMTQ2; t=IBkdPrg1TmqmwBQXvgI-txjC; __Host-js_csrf=IBkdPrg1TmqmwBQXvgI-txjC; __Host-ss=EY2fO9sdY8; locale=en
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.dropbox.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundStrict-Transport-Security: max-age=31536000; includeSubDomainsContent-Length: 1233Content-Type: text/htmlDate: Thu, 25 Apr 2024 20:39:05 GMTServer: envoyCache-Control: no-cache, no-storeVary: Accept-EncodingX-Dropbox-Response-Origin: remoteX-Dropbox-Request-Id: f5fa2e066cbb4604ba80a192e84ade16Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/0@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1828 --field-trial-handle=1956,i,3247001600556690069,7833688900923320994,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1828 --field-trial-handle=1956,i,3247001600556690069,7833688900923320994,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www-env.dropbox-dns.com
162.125.9.18
truefalse
    unknown
    www.google.com
    64.233.177.105
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        www.dropbox.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQfalse
            high
            https://www.dropbox.com/favicon.icofalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              162.125.9.18
              www-env.dropbox-dns.comUnited States
              19679DROPBOXUSfalse
              64.233.177.105
              www.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.251.15.99
              unknownUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1431881
              Start date and time:2024-04-25 22:38:09 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 14s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/0@6/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 173.194.219.94, 64.233.177.100, 64.233.177.113, 64.233.177.139, 64.233.177.138, 64.233.177.102, 64.233.177.101, 142.250.9.84, 34.104.35.123, 20.12.23.50, 23.40.205.26, 23.40.205.51, 23.40.205.35, 13.85.23.206, 192.229.211.108, 20.166.126.56, 142.250.105.94
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Apr 25, 2024 22:38:54.700934887 CEST49675443192.168.2.4173.222.162.32
              Apr 25, 2024 22:39:04.309298038 CEST49675443192.168.2.4173.222.162.32
              Apr 25, 2024 22:39:05.131830931 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.131912947 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.132004023 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.132286072 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.132312059 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.132365942 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.132571936 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.132603884 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.132824898 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.132831097 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.469930887 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.470242023 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.470272064 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.471149921 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.471292019 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.471363068 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.471477985 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.471537113 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.472877026 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.472951889 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.473048925 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.473109961 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.473121881 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.473129988 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.473567009 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.473654985 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.513092995 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.528251886 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.528289080 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.575365067 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.722687960 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.722711086 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.722784042 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.722886086 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.722887039 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.724292994 CEST49739443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.724313974 CEST44349739162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.788834095 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:05.832151890 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.997001886 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.997184992 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:05.997247934 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:06.002203941 CEST49738443192.168.2.4162.125.9.18
              Apr 25, 2024 22:39:06.002263069 CEST44349738162.125.9.18192.168.2.4
              Apr 25, 2024 22:39:07.703630924 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.703705072 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:07.703907967 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.704530954 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.704567909 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:07.942091942 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:07.960787058 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.960844994 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:07.964984894 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:07.965101004 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.978853941 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:07.979067087 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:08.028002977 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:08.028059959 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:08.074851990 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:08.332581043 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.332664013 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.332899094 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.336133003 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.336177111 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.563002110 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.563144922 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.569992065 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.570025921 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.570261955 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.621843100 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.655782938 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.696121931 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.778316975 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.778376102 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.778521061 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.778717041 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.778759956 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.778795004 CEST49743443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.778827906 CEST44349743184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.813623905 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.813698053 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:08.813788891 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.814140081 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:08.814165115 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.036981106 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.037074089 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.038306952 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.038328886 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.038594007 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.039805889 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.080122948 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.255575895 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.255666018 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.255718946 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.257000923 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.257024050 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:09.257039070 CEST49744443192.168.2.4184.31.62.93
              Apr 25, 2024 22:39:09.257046938 CEST44349744184.31.62.93192.168.2.4
              Apr 25, 2024 22:39:17.943880081 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:17.943972111 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:17.944160938 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:19.750545979 CEST49742443192.168.2.464.233.177.105
              Apr 25, 2024 22:39:19.750564098 CEST4434974264.233.177.105192.168.2.4
              Apr 25, 2024 22:39:21.708231926 CEST804972369.164.42.0192.168.2.4
              Apr 25, 2024 22:39:21.708437920 CEST4972380192.168.2.469.164.42.0
              Apr 25, 2024 22:39:21.708478928 CEST4972380192.168.2.469.164.42.0
              Apr 25, 2024 22:39:21.818105936 CEST804972369.164.42.0192.168.2.4
              Apr 25, 2024 22:40:07.468170881 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:07.468216896 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.468283892 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:07.468533993 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:07.468548059 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.699588060 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.699846983 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:07.699906111 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.701082945 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.701427937 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:07.701611042 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:07.747134924 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:11.190131903 CEST4972480192.168.2.423.47.204.82
              Apr 25, 2024 22:40:11.299596071 CEST804972423.47.204.82192.168.2.4
              Apr 25, 2024 22:40:11.299671888 CEST4972480192.168.2.423.47.204.82
              Apr 25, 2024 22:40:17.713541031 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:17.713670969 CEST44349752142.251.15.99192.168.2.4
              Apr 25, 2024 22:40:17.713825941 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:19.609800100 CEST49752443192.168.2.4142.251.15.99
              Apr 25, 2024 22:40:19.609838009 CEST44349752142.251.15.99192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Apr 25, 2024 22:39:03.103857040 CEST53546501.1.1.1192.168.2.4
              Apr 25, 2024 22:39:03.108546019 CEST53634701.1.1.1192.168.2.4
              Apr 25, 2024 22:39:03.929214954 CEST53579681.1.1.1192.168.2.4
              Apr 25, 2024 22:39:05.020029068 CEST5256253192.168.2.41.1.1.1
              Apr 25, 2024 22:39:05.020273924 CEST5602153192.168.2.41.1.1.1
              Apr 25, 2024 22:39:05.130906105 CEST53560211.1.1.1192.168.2.4
              Apr 25, 2024 22:39:05.130940914 CEST53525621.1.1.1192.168.2.4
              Apr 25, 2024 22:39:07.198556900 CEST5799053192.168.2.41.1.1.1
              Apr 25, 2024 22:39:07.201086044 CEST5120153192.168.2.41.1.1.1
              Apr 25, 2024 22:39:07.309362888 CEST53579901.1.1.1192.168.2.4
              Apr 25, 2024 22:39:07.311045885 CEST53512011.1.1.1192.168.2.4
              Apr 25, 2024 22:39:20.937346935 CEST53535481.1.1.1192.168.2.4
              Apr 25, 2024 22:39:22.753582954 CEST138138192.168.2.4192.168.2.255
              Apr 25, 2024 22:39:39.682760954 CEST53516361.1.1.1192.168.2.4
              Apr 25, 2024 22:40:02.484262943 CEST53587681.1.1.1192.168.2.4
              Apr 25, 2024 22:40:02.994117975 CEST53630711.1.1.1192.168.2.4
              Apr 25, 2024 22:40:07.354146004 CEST6246153192.168.2.41.1.1.1
              Apr 25, 2024 22:40:07.354274988 CEST6526353192.168.2.41.1.1.1
              Apr 25, 2024 22:40:07.467051983 CEST53652631.1.1.1192.168.2.4
              Apr 25, 2024 22:40:07.467102051 CEST53624611.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Apr 25, 2024 22:39:05.020029068 CEST192.168.2.41.1.1.10x72b8Standard query (0)www.dropbox.comA (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:05.020273924 CEST192.168.2.41.1.1.10xfe45Standard query (0)www.dropbox.com65IN (0x0001)false
              Apr 25, 2024 22:39:07.198556900 CEST192.168.2.41.1.1.10x5a38Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.201086044 CEST192.168.2.41.1.1.10xb00bStandard query (0)www.google.com65IN (0x0001)false
              Apr 25, 2024 22:40:07.354146004 CEST192.168.2.41.1.1.10xb197Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.354274988 CEST192.168.2.41.1.1.10x89bfStandard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Apr 25, 2024 22:39:05.130906105 CEST1.1.1.1192.168.2.40xfe45No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:39:05.130940914 CEST1.1.1.1192.168.2.40x72b8No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:39:05.130940914 CEST1.1.1.1192.168.2.40x72b8No error (0)www-env.dropbox-dns.com162.125.9.18A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.105A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.99A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.106A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.104A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.103A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.309362888 CEST1.1.1.1192.168.2.40x5a38No error (0)www.google.com64.233.177.147A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:07.311045885 CEST1.1.1.1192.168.2.40xb00bNo error (0)www.google.com65IN (0x0001)false
              Apr 25, 2024 22:39:18.885814905 CEST1.1.1.1192.168.2.40x8a75No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:39:18.885814905 CEST1.1.1.1192.168.2.40x8a75No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:36.028516054 CEST1.1.1.1192.168.2.40x595bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:39:36.028516054 CEST1.1.1.1192.168.2.40x595bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 25, 2024 22:39:54.812915087 CEST1.1.1.1192.168.2.40x4810No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:39:54.812915087 CEST1.1.1.1192.168.2.40x4810No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467051983 CEST1.1.1.1192.168.2.40x89bfNo error (0)www.google.com65IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.99A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.103A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.104A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.106A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.105A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:07.467102051 CEST1.1.1.1192.168.2.40xb197No error (0)www.google.com142.251.15.147A (IP address)IN (0x0001)false
              Apr 25, 2024 22:40:16.170852900 CEST1.1.1.1192.168.2.40x46bbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Apr 25, 2024 22:40:16.170852900 CEST1.1.1.1192.168.2.40x46bbNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • www.dropbox.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449739162.125.9.184431852C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-25 20:39:05 UTC708OUTGET /l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ HTTP/1.1
              Host: www.dropbox.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-04-25 20:39:05 UTC3263INHTTP/1.1 200 OK
              Content-Type: image/jpeg
              Content-Security-Policy: base-uri 'self' ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; connect-src https://* ws://127.0.0.1:*/ws wss://dsimports.dropbox.com/ ; default-src 'none' ; font-src https://* data: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; frame-src https://* carousel: dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss: ; img-src https://* data: blob: ; media-src https://* blob: ; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ ; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist ; script-src 'unsafe-eval' https://www.dropbox.com/static/api/ https://www.dropbox.com/pithos/* https://www.dropbox.com/page_success/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://canny.io/sdk.js 'nonce-z70yEVPEOLjgsw3pPWpr' ; style-src https://* 'unsafe-inline' 'unsafe-eval' ; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js blob:
              Content-Security-Policy: report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-z70yEVPEOLjgsw3pPWpr' 'nonce-QFnoRI8lJ0w77/PRzT+H'
              Referrer-Policy: strict-origin-when-cross-origin
              Set-Cookie: gvc=MTY3ODcwNDExMzE1Nzk0Mjc4NTA0NjQ4MTk5MDE3ODY4NDMwMTQ2; expires=Tue, 24 Apr 2029 20:39:05 GMT; HttpOnly; Path=/; SameSite=None; Secure
              Set-Cookie: t=IBkdPrg1TmqmwBQXvgI-txjC; Domain=dropbox.com; expires=Sun, 25 Apr 2027 20:39:05 GMT; HttpOnly; Path=/; SameSite=None; Secure
              Set-Cookie: __Host-js_csrf=IBkdPrg1TmqmwBQXvgI-txjC; expires=Sun, 25 Apr 2027 20:39:05 GMT; Path=/; SameSite=None; Secure
              Set-Cookie: __Host-ss=EY2fO9sdY8; expires=Sun, 25 Apr 2027 20:39:05 GMT; HttpOnly; Path=/; SameSite=Strict; Secure
              Set-Cookie: locale=en; Domain=dropbox.com; expires=Tue, 24 Apr 2029 20:39:05 GMT; Path=/; SameSite=None; Secure
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-Permitted-Cross-Domain-Policies: none
              X-Server-Response-Time: 8
              X-Xss-Protection: 1; mode=block
              Date: Thu, 25 Apr 2024 20:39:05 GMT
              Server: envoy
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Cache-Control: no-cache, no-store
              X-Dropbox-Response-Origin: far_remote
              X-Dropbox-Request-Id: a4c1d9da750a46f28991949b3ad7ecbc
              Connection: close
              Transfer-Encoding: chunked
              2024-04-25 20:39:05 UTC643INData Raw: 32 37 37 0d 0a ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff db 00 43 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff c0 00 11 08 00 01 00 01 03 01 22 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14
              Data Ascii: 277JFIFCC"}!1AQa"q


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449738162.125.9.184431852C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-04-25 20:39:05 UTC804OUTGET /favicon.ico HTTP/1.1
              Host: www.dropbox.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              Cookie: gvc=MTY3ODcwNDExMzE1Nzk0Mjc4NTA0NjQ4MTk5MDE3ODY4NDMwMTQ2; t=IBkdPrg1TmqmwBQXvgI-txjC; __Host-js_csrf=IBkdPrg1TmqmwBQXvgI-txjC; __Host-ss=EY2fO9sdY8; locale=en
              2024-04-25 20:39:05 UTC357INHTTP/1.1 404 Not Found
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Content-Length: 1233
              Content-Type: text/html
              Date: Thu, 25 Apr 2024 20:39:05 GMT
              Server: envoy
              Cache-Control: no-cache, no-store
              Vary: Accept-Encoding
              X-Dropbox-Response-Origin: remote
              X-Dropbox-Request-Id: f5fa2e066cbb4604ba80a192e84ade16
              Connection: close
              2024-04-25 20:39:05 UTC1233INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 44 72 6f 70 62 6f 78 20 2d 20 34 30 34 3c 2f 74 69 74 6c 65 3e 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 66 6c 2e 64 72 6f 70 62 6f 78 73 74 61 74 69 63 2e 63 6f 6d 2f 73 74 61 74 69 63 2f 6d 65 74 61 73 65 72 76 65
              Data Ascii: <!DOCTYPE html><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1" /><title>Dropbox - 404</title><link href="https://cfl.dropboxstatic.com/static/metaserve


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449743184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-25 20:39:08 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-25 20:39:08 UTC467INHTTP/1.1 200 OK
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0790)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=123867
              Date: Thu, 25 Apr 2024 20:39:08 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449744184.31.62.93443
              TimestampBytes transferredDirectionData
              2024-04-25 20:39:09 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-04-25 20:39:09 UTC515INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/0758)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-eus-z1
              Cache-Control: public, max-age=123866
              Date: Thu, 25 Apr 2024 20:39:09 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-04-25 20:39:09 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:22:38:57
              Start date:25/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:22:39:01
              Start date:25/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1828 --field-trial-handle=1956,i,3247001600556690069,7833688900923320994,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:22:39:04
              Start date:25/04/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dropbox.com/l/scl/AADBdXGE7XCfkblPQ8WEsvostiGPEFBlv_E&d=DwMFaQ"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly