Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php

Overview

General Information

Sample URL:https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
Analysis ID:1438535
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
LLM detected suspicious URL
LLM detected suspicious webpage text

Classification

  • System is w10x64
  • chrome.exe (PID: 4340 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,2594830658058363299,1807913107444712400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6456 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://ss-corp.conohawing.com/favicon.icoAvira URL Cloud: Label: phishing

Phishing

barindex
Source: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/LLM: Score: 8 Reasons: The URL provided shows signs of typosquatting, which is a type of cyber attack that relies on creating domain names that are similar to legitimate ones but with slight misspellings or other changes to trick users into visiting them. In this case, the legitimate domain 'ss-corp.com' has been replaced with 'ss-corp.conohawing.com', which is likely an attempt to impersonate the legitimate site. The risk score of 8 indicates a high level of concern, and users should avoid visiting this URL or providing any sensitive information if they do visit it. DOM: 1.1.pages.csv
Source: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/LLM: Score: 7 Reasons: The text suggests a 'Forbidden' message, which is often associated with attempted unauthorized access. The URL contains a suspicious domain 'conohawing.com' which does not match the expected domain 'ss-corp.com'. Additionally, the path contains a mix of letters and numbers that do not form a meaningful resource name. These factors indicate a high probability of a phishing or malicious site. DOM: 1.1.pages.csv
Source: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 104.125.88.106:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.125.88.106:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 104.125.88.106
Source: unknownTCP traffic detected without corresponding DNS query: 23.32.75.35
Source: unknownTCP traffic detected without corresponding DNS query: 23.32.75.41
Source: unknownTCP traffic detected without corresponding DNS query: 23.32.75.35
Source: unknownTCP traffic detected without corresponding DNS query: 23.32.75.41
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /wp-admin/user/dd.php HTTP/1.1Host: www.snookerandpoolservices.co.ukConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.snookerandpoolservices.co.ukConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/ HTTP/1.1Host: ss-corp.conohawing.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.snookerandpoolservices.co.uk/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1Host: www.snookerandpoolservices.co.ukConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: ss-corp.conohawing.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: www.snookerandpoolservices.co.uk
Source: global trafficDNS traffic detected: DNS query: ss-corp.conohawing.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginxDate: Wed, 08 May 2024 18:24:56 GMTContent-Type: text/html; charset=iso-8859-1Content-Length: 199Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 08 May 2024 18:24:56 GMTContent-Type: text/html; charset=iso-8859-1Content-Length: 196Connection: close
Source: chromecache_42.2.drString found in binary or memory: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 104.125.88.106:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.125.88.106:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: classification engineClassification label: mal56.phis.win@17/6@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,2594830658058363299,1807913107444712400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,2594830658058363299,1807913107444712400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://www.snookerandpoolservices.co.uk/favicon.ico0%Avira URL Cloudsafe
https://www.snookerandpoolservices.co.uk/wp-includes/images/w-logo-blue-white-bg.png0%Avira URL Cloudsafe
https://ss-corp.conohawing.com/favicon.ico100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    ss-corp.conohawing.com
    118.27.122.85
    truetrue
      unknown
      www.google.com
      142.250.69.196
      truefalse
        high
        www.snookerandpoolservices.co.uk
        46.30.213.169
        truefalse
          unknown
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://www.snookerandpoolservices.co.uk/wp-includes/images/w-logo-blue-white-bg.pngfalse
            • Avira URL Cloud: safe
            unknown
            https://www.snookerandpoolservices.co.uk/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/true
              unknown
              https://ss-corp.conohawing.com/favicon.icofalse
              • Avira URL Cloud: phishing
              unknown
              https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.phpfalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                46.30.213.169
                www.snookerandpoolservices.co.ukDenmark
                51468ONECOMDKfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.69.196
                www.google.comUnited States
                15169GOOGLEUSfalse
                118.27.122.85
                ss-corp.conohawing.comJapan7506INTERQGMOInternetIncJPtrue
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1438535
                Start date and time:2024-05-08 20:24:02 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 2s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:8
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal56.phis.win@17/6@6/5
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.251.33.99, 173.194.202.84, 142.251.33.110, 34.104.35.123, 13.85.23.86, 199.232.214.172, 192.229.211.108, 13.95.31.18, 20.3.187.198
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
                No simulations
                InputOutput
                URL: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
                {
                "riskscore": 7,
                "reasons": "The text suggests a 'Forbidden' message, which is often associated with attempted unauthorized access. The URL contains a suspicious domain 'conohawing.com' which does not match the expected domain 'ss-corp.com'. Additionally, the path contains a mix of letters and numbers that do not form a meaningful resource name. These factors indicate a high probability of a phishing or malicious site."
                }"
                Forbidden You don't have permission to access this resource. 
                URL: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
                {
                    "riskscore": 8,
                    "reasons": "The URL provided shows signs of typosquatting, which is a type of cyber attack that relies on creating domain names that are similar to legitimate ones but with slight misspellings or other changes to trick users into visiting them. In this case, the legitimate domain 'ss-corp.com' has been replaced with 'ss-corp.conohawing.com', which is likely an attempt to impersonate the legitimate site. The risk score of 8 indicates a high level of concern, and users should avoid visiting this URL or providing any sensitive information if they do visit it."
                }"
                https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):196
                Entropy (8bit):5.098952451791238
                Encrypted:false
                SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezocKqD:J0+oxBeRmR9etdzRxGez1T
                MD5:62962DAA1B19BBCC2DB10B7BFD531EA6
                SHA1:D64BAE91091EDA6A7532EBEC06AA70893B79E1F8
                SHA-256:80C3FE2AE1062ABF56456F52518BD670F9EC3917B7F85E152B347AC6B6FAF880
                SHA-512:9002A0475FDB38541E78048709006926655C726E93E823B84E2DBF5B53FD539A5342E7266447D23DB0E5528E27A19961B115B180C94F2272FF124C7E5C8304E7
                Malicious:false
                Reputation:low
                URL:https://ss-corp.conohawing.com/favicon.ico
                Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.</body></html>.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):211
                Entropy (8bit):5.194854532682102
                Encrypted:false
                SSDEEP:3:nmJYQqRJA/XM2AQezpEHjJMzVJu+1zWNVYj4VyQKTLnK4nGMSKKrDyIEJylNQX/6:KYl8PeKMRJVCNOUjYKuDSRSiQX/5K9
                MD5:FA35929C2FCADE9EACA9410EECE6049D
                SHA1:37111B197016CD46F5CCB78CA643197AA65FC071
                SHA-256:B1B8E614301257D2CC475140EBA625944FEF801206CC1A3AFFE163B07845D531
                SHA-512:E697E94716529C1B14066E005BD138E0525E1C218AD4C823650BC60E6E12DB240963CCB96769846BC4B93B9EA3C011D33DE3DE73EBFA3A1E89E562FC67B7811B
                Malicious:false
                Reputation:low
                URL:https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
                Preview:<meta charset="UTF-8">..<title> Sygeforsikringen Danmark </title>..<meta http-equiv="refresh" content="0; url=https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/"/>
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):199
                Entropy (8bit):5.112530855532291
                Encrypted:false
                SSDEEP:6:pn0+Dy9xwIgsozEr6VyF02xxdGzsQWr+KqD:J0+oxBgsozR4F0+dgsQo+T
                MD5:BB8F534FBFF5EE61A95AF9C4740AE043
                SHA1:832E403D42AAC1FEC93E4F602338544D3FD2E4F1
                SHA-256:5B13FB5957B84EF7BB9D0B6CD509C947FF6A37D67EFDAC2B896DDD3B908AAD10
                SHA-512:EB423CA8E0F3E026A367130044B1857A1368097F9AC3C8FCAA523FA5E2785437FBC328397B5C6582FB0C872CFF44E70CF0120D874D825472806ADC46ACDBFFDD
                Malicious:false
                Reputation:low
                URL:https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
                Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access this resource.</p>.</body></html>.
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                May 8, 2024 20:24:43.996891022 CEST49675443192.168.2.4173.222.162.32
                May 8, 2024 20:24:44.325117111 CEST49678443192.168.2.4104.46.162.224
                May 8, 2024 20:24:53.081543922 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.081568956 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.081645966 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.082003117 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.082046986 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.082186937 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.082201004 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.082216024 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.082443953 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.082456112 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.605156898 CEST49675443192.168.2.4173.222.162.32
                May 8, 2024 20:24:53.711179018 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.711772919 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.765587091 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.765592098 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.925358057 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.925371885 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.925798893 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.925826073 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.926440954 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.926453114 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.926496029 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.926901102 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.926917076 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.926950932 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.932137012 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.932250023 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.936110973 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.936312914 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:53.938486099 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.938491106 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:53.981066942 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.981071949 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:53.981091022 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:54.035214901 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:54.333056927 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:54.333141088 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:54.333194017 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:54.335647106 CEST49736443192.168.2.446.30.213.169
                May 8, 2024 20:24:54.335666895 CEST4434973646.30.213.169192.168.2.4
                May 8, 2024 20:24:54.491128922 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:54.532118082 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:55.187796116 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.187841892 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.187994957 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.188513994 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.188528061 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.380584955 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.380637884 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:55.380705118 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.381675005 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.381721020 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:55.381824017 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.382669926 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.382683992 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:55.408529043 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:55.408544064 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:55.528146982 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.528554916 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.528590918 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.529582977 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.529664993 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.538367987 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.538438082 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.589288950 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.589324951 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:24:55.637218952 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:24:55.649131060 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:55.649234056 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:55.649291039 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:55.650516987 CEST49737443192.168.2.446.30.213.169
                May 8, 2024 20:24:55.650536060 CEST4434973746.30.213.169192.168.2.4
                May 8, 2024 20:24:55.663556099 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:55.663594007 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:55.663681030 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:55.664017916 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:55.664026976 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:55.893003941 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:55.893043041 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:55.893115044 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:55.896608114 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:55.896619081 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:55.970242023 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:55.986356020 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.015719891 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.026655912 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.114854097 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.114875078 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.116131067 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.116209030 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.117786884 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.117808104 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.118976116 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.119040966 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.169018984 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.169131994 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.169698954 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.169812918 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.170988083 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.171000957 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.217276096 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.217279911 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.217302084 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.230170965 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.230259895 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.232754946 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.232772112 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.233028889 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.265625000 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.276014090 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.291207075 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.291482925 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:56.291496038 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.291779995 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.292068958 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:56.292143106 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.292206049 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:56.320120096 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.336121082 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.551146030 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.551232100 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.551301003 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.551563025 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.551660061 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.551716089 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.551742077 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.551742077 CEST49743443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.551753998 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.551760912 CEST44349743104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.552382946 CEST49740443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.552401066 CEST44349740118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.588352919 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.588382959 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.588527918 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.588814974 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.588826895 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.796535969 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:56.801481962 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:56.801575899 CEST4434974246.30.213.169192.168.2.4
                May 8, 2024 20:24:56.801687956 CEST49742443192.168.2.446.30.213.169
                May 8, 2024 20:24:56.844116926 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:56.917778015 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.917844057 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.949897051 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:56.949914932 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.950133085 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:56.954334974 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:57.000106096 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:57.085489988 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:57.085573912 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:57.085691929 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:57.089287043 CEST49741443192.168.2.4118.27.122.85
                May 8, 2024 20:24:57.089306116 CEST44349741118.27.122.85192.168.2.4
                May 8, 2024 20:24:57.256488085 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:57.256628990 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:57.256680012 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:57.258584023 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:57.258599043 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:24:57.258609056 CEST49744443192.168.2.4104.125.88.106
                May 8, 2024 20:24:57.258614063 CEST44349744104.125.88.106192.168.2.4
                May 8, 2024 20:25:05.523902893 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:25:05.523964882 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:25:05.524012089 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:25:06.987200022 CEST49739443192.168.2.4142.250.69.196
                May 8, 2024 20:25:06.987224102 CEST44349739142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.456069946 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:25:55.456096888 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.456213951 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:25:55.456496954 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:25:55.456511974 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.791310072 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.791802883 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:25:55.791817904 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.792109013 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.792649031 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:25:55.792706966 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:25:55.839468002 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:26:03.261480093 CEST4972380192.168.2.423.32.75.35
                May 8, 2024 20:26:03.261542082 CEST4972480192.168.2.423.32.75.41
                May 8, 2024 20:26:03.424012899 CEST804972323.32.75.35192.168.2.4
                May 8, 2024 20:26:03.424038887 CEST804972423.32.75.41192.168.2.4
                May 8, 2024 20:26:03.424083948 CEST4972380192.168.2.423.32.75.35
                May 8, 2024 20:26:03.424118042 CEST4972480192.168.2.423.32.75.41
                May 8, 2024 20:26:05.783339024 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:26:05.783413887 CEST44349753142.250.69.196192.168.2.4
                May 8, 2024 20:26:05.783572912 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:26:06.981710911 CEST49753443192.168.2.4142.250.69.196
                May 8, 2024 20:26:06.981733084 CEST44349753142.250.69.196192.168.2.4
                TimestampSource PortDest PortSource IPDest IP
                May 8, 2024 20:24:50.950804949 CEST53581811.1.1.1192.168.2.4
                May 8, 2024 20:24:50.968162060 CEST53637011.1.1.1192.168.2.4
                May 8, 2024 20:24:51.900156021 CEST53576251.1.1.1192.168.2.4
                May 8, 2024 20:24:52.475159883 CEST5282653192.168.2.41.1.1.1
                May 8, 2024 20:24:52.475322962 CEST6524053192.168.2.41.1.1.1
                May 8, 2024 20:24:52.964757919 CEST53652401.1.1.1192.168.2.4
                May 8, 2024 20:24:53.080737114 CEST53528261.1.1.1192.168.2.4
                May 8, 2024 20:24:54.482659101 CEST5533453192.168.2.41.1.1.1
                May 8, 2024 20:24:54.482863903 CEST5541853192.168.2.41.1.1.1
                May 8, 2024 20:24:54.999023914 CEST5654453192.168.2.41.1.1.1
                May 8, 2024 20:24:54.999191999 CEST6481453192.168.2.41.1.1.1
                May 8, 2024 20:24:55.036381006 CEST53554181.1.1.1192.168.2.4
                May 8, 2024 20:24:55.164169073 CEST53648141.1.1.1192.168.2.4
                May 8, 2024 20:24:55.164329052 CEST53565441.1.1.1192.168.2.4
                May 8, 2024 20:24:55.374753952 CEST53553341.1.1.1192.168.2.4
                May 8, 2024 20:25:10.123888969 CEST53637351.1.1.1192.168.2.4
                May 8, 2024 20:25:14.848390102 CEST138138192.168.2.4192.168.2.255
                May 8, 2024 20:25:29.264647961 CEST53555231.1.1.1192.168.2.4
                May 8, 2024 20:25:50.505873919 CEST53652061.1.1.1192.168.2.4
                May 8, 2024 20:25:52.265666008 CEST53541831.1.1.1192.168.2.4
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                May 8, 2024 20:24:52.475159883 CEST192.168.2.41.1.1.10x1521Standard query (0)www.snookerandpoolservices.co.ukA (IP address)IN (0x0001)false
                May 8, 2024 20:24:52.475322962 CEST192.168.2.41.1.1.10x5b63Standard query (0)www.snookerandpoolservices.co.uk65IN (0x0001)false
                May 8, 2024 20:24:54.482659101 CEST192.168.2.41.1.1.10x1d77Standard query (0)ss-corp.conohawing.comA (IP address)IN (0x0001)false
                May 8, 2024 20:24:54.482863903 CEST192.168.2.41.1.1.10xd526Standard query (0)ss-corp.conohawing.com65IN (0x0001)false
                May 8, 2024 20:24:54.999023914 CEST192.168.2.41.1.1.10xdf0fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                May 8, 2024 20:24:54.999191999 CEST192.168.2.41.1.1.10x800bStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                May 8, 2024 20:24:53.080737114 CEST1.1.1.1192.168.2.40x1521No error (0)www.snookerandpoolservices.co.uk46.30.213.169A (IP address)IN (0x0001)false
                May 8, 2024 20:24:55.164169073 CEST1.1.1.1192.168.2.40x800bNo error (0)www.google.com65IN (0x0001)false
                May 8, 2024 20:24:55.164329052 CEST1.1.1.1192.168.2.40xdf0fNo error (0)www.google.com142.250.69.196A (IP address)IN (0x0001)false
                May 8, 2024 20:24:55.374753952 CEST1.1.1.1192.168.2.40x1d77No error (0)ss-corp.conohawing.com118.27.122.85A (IP address)IN (0x0001)false
                May 8, 2024 20:25:07.420063019 CEST1.1.1.1192.168.2.40x6838No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                May 8, 2024 20:25:07.420063019 CEST1.1.1.1192.168.2.40x6838No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                May 8, 2024 20:25:07.935108900 CEST1.1.1.1192.168.2.40x4fc2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 20:25:07.935108900 CEST1.1.1.1192.168.2.40x4fc2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 20:25:21.162476063 CEST1.1.1.1192.168.2.40x1203No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 20:25:21.162476063 CEST1.1.1.1192.168.2.40x1203No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 20:25:44.363631964 CEST1.1.1.1192.168.2.40x110fNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 20:25:44.363631964 CEST1.1.1.1192.168.2.40x110fNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                May 8, 2024 20:26:03.613409042 CEST1.1.1.1192.168.2.40x8b9bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                May 8, 2024 20:26:03.613409042 CEST1.1.1.1192.168.2.40x8b9bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • www.snookerandpoolservices.co.uk
                • https:
                  • ss-corp.conohawing.com
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.44973646.30.213.1694435352C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:53 UTC695OUTGET /wp-admin/user/dd.php HTTP/1.1
                Host: www.snookerandpoolservices.co.uk
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-05-08 18:24:54 UTC315INHTTP/1.1 200 OK
                Date: Wed, 08 May 2024 18:24:54 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.19
                Vary: Accept-Encoding
                Content-Type: text/html; charset=UTF-8
                X-Onecom-Cluster-Name:
                X-Varnish: 2040149528
                Age: 0
                Via: 1.1 webcache2 (Varnish/trunk)
                Accept-Ranges: bytes
                Content-Length: 211
                Connection: close
                2024-05-08 18:24:54 UTC211INData Raw: 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0d 0a 3c 74 69 74 6c 65 3e 20 53 79 67 65 66 6f 72 73 69 6b 72 69 6e 67 65 6e 20 44 61 6e 6d 61 72 6b 20 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 72 65 66 72 65 73 68 22 20 63 6f 6e 74 65 6e 74 3d 22 30 3b 20 75 72 6c 3d 68 74 74 70 73 3a 2f 2f 73 73 2d 63 6f 72 70 2e 63 6f 6e 6f 68 61 77 69 6e 67 2e 63 6f 6d 2f 64 2f 64 6b 2f 25 43 33 25 38 35 72 73 72 61 70 70 6f 72 2f 6f 6d 2f 73 79 67 65 6a 6f 75 72 6e 61 6c 65 72 2f 30 32 34 2f 39 38 35 32 38 35 32 30 30 30 36 36 36 30 30 30 35 35 36 2f 64 62 2f 72 65 2f 22 2f 3e
                Data Ascii: <meta charset="UTF-8"><title> Sygeforsikringen Danmark </title><meta http-equiv="refresh" content="0; url=https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/"/>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.44973746.30.213.1694435352C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:54 UTC640OUTGET /favicon.ico HTTP/1.1
                Host: www.snookerandpoolservices.co.uk
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-05-08 18:24:55 UTC478INHTTP/1.1 302 Found
                Date: Wed, 08 May 2024 18:24:54 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.19
                Link: <https://www.snookerandpoolservices.co.uk/wp-json/>; rel="https://api.w.org/"
                X-Redirect-By: WordPress
                Location: https://www.snookerandpoolservices.co.uk/wp-includes/images/w-logo-blue-white-bg.png
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8
                X-Onecom-Cluster-Name:
                X-Varnish: 2160233390
                Age: 0
                Via: 1.1 webcache2 (Varnish/trunk)
                Connection: close


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.449740118.27.122.854435352C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:56 UTC770OUTGET /d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/ HTTP/1.1
                Host: ss-corp.conohawing.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: cross-site
                Sec-Fetch-Mode: navigate
                Sec-Fetch-Dest: document
                Referer: https://www.snookerandpoolservices.co.uk/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-05-08 18:24:56 UTC163INHTTP/1.1 403 Forbidden
                Server: nginx
                Date: Wed, 08 May 2024 18:24:56 GMT
                Content-Type: text/html; charset=iso-8859-1
                Content-Length: 199
                Connection: close
                2024-05-08 18:24:56 UTC199INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.449743104.125.88.106443
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:56 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-05-08 18:24:56 UTC466INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (sac/2518)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-eus-z1
                Cache-Control: public, max-age=45514
                Date: Wed, 08 May 2024 18:24:56 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.44974246.30.213.1694435352C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:56 UTC672OUTGET /wp-includes/images/w-logo-blue-white-bg.png HTTP/1.1
                Host: www.snookerandpoolservices.co.uk
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.449741118.27.122.854435352C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:56 UTC667OUTGET /favicon.ico HTTP/1.1
                Host: ss-corp.conohawing.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://ss-corp.conohawing.com/d/dk/%C3%85rsrappor/om/sygejournaler/024/9852852000666000556/db/re/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-05-08 18:24:57 UTC163INHTTP/1.1 404 Not Found
                Server: nginx
                Date: Wed, 08 May 2024 18:24:56 GMT
                Content-Type: text/html; charset=iso-8859-1
                Content-Length: 196
                Connection: close
                2024-05-08 18:24:57 UTC196INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.449744104.125.88.106443
                TimestampBytes transferredDirectionData
                2024-05-08 18:24:56 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-05-08 18:24:57 UTC538INHTTP/1.1 200 OK
                Content-Type: application/octet-stream
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                X-Azure-Ref: 0MNkrYwAAAADiUL7L3dxqSIABzBrl++yWQ082QUEzMTUwODEwMDIxAGNlZmMyNTgzLWE5YjItNDRhNy05NzU1LWI3NmQxN2UwNWY3Zg==
                Cache-Control: public, max-age=28983
                Date: Wed, 08 May 2024 18:24:57 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-05-08 18:24:57 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:20:24:47
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:20:24:49
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2204,i,2594830658058363299,1807913107444712400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:20:24:51
                Start date:08/05/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.snookerandpoolservices.co.uk/wp-admin/user/dd.php"
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly