Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://your@portal.investistratix.com

Overview

General Information

Sample URL:http://your@portal.investistratix.com
Analysis ID:1637563
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates files inside the system directory
Deletes files inside the Windows folder
URL contains potential PII (phishing indication)

Classification

  • System is w10x64
  • chrome.exe (PID: 6336 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6716 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7408 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3288 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7652 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://your@portal.investistratix.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://your@portal.investistratix.comAvira URL Cloud: detection malicious, Label: malware
Source: https://portal.investistratix.com/favicon.icoAvira URL Cloud: Label: malware
Source: https://portal.investistratix.com/Avira URL Cloud: Label: malware
Source: https://portal.investistratix.com/?C=N;O=DAvira URL Cloud: Label: malware
Source: https://portal.investistratix.com/?C=N;O=AAvira URL Cloud: Label: malware
Source: http://your@portal.investistratix.comSample URL: PII: your@portal.investistratix.com
Source: https://your@portal.investistratix.com/HTTP Parser: No favicon
Source: https://your@portal.investistratix.com/?C=N;O=DHTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.96.106
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.35
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.35
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: portal.investistratix.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://portal.investistratix.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?C=N;O=D HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://portal.investistratix.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?C=N;O=A HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://portal.investistratix.com/?C=N;O=DAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?C=N;O=D HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://portal.investistratix.com/?C=N;O=AAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?C=N;O=A HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://portal.investistratix.com/?C=N;O=DAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?C=N;O=D HTTP/1.1Host: portal.investistratix.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://portal.investistratix.com/?C=N;O=AAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: portal.investistratix.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 13 Mar 2025 16:43:39 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6336_1159721609Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6336_1159721609Jump to behavior
Source: classification engineClassification label: mal56.win@24/8@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3288 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://your@portal.investistratix.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3288 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://your@portal.investistratix.com100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://portal.investistratix.com/favicon.ico100%Avira URL Cloudmalware
https://portal.investistratix.com/100%Avira URL Cloudmalware
https://portal.investistratix.com/?C=N;O=D100%Avira URL Cloudmalware
https://portal.investistratix.com/?C=N;O=A100%Avira URL Cloudmalware
NameIPActiveMaliciousAntivirus DetectionReputation
portal.investistratix.com
199.188.207.196
truefalse
    unknown
    www.google.com
    142.250.186.132
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://your@portal.investistratix.com/?C=N;O=Afalse
        unknown
        https://portal.investistratix.com/false
        • Avira URL Cloud: malware
        unknown
        https://portal.investistratix.com/?C=N;O=Dfalse
        • Avira URL Cloud: malware
        unknown
        https://portal.investistratix.com/?C=N;O=Afalse
        • Avira URL Cloud: malware
        unknown
        https://your@portal.investistratix.com/?C=N;O=Dfalse
          unknown
          https://portal.investistratix.com/favicon.icofalse
          • Avira URL Cloud: malware
          unknown
          https://your@portal.investistratix.com/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            199.188.207.196
            portal.investistratix.comUnited States
            22612NAMECHEAP-NETUSfalse
            142.250.186.132
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            192.168.2.5
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1637563
            Start date and time:2025-03-13 17:42:34 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 2s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://your@portal.investistratix.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:17
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal56.win@24/8@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, BackgroundTransferHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.16.206, 216.58.206.35, 142.250.185.142, 74.125.206.84, 142.250.184.227, 172.217.18.14, 216.58.206.46, 142.250.186.174, 142.250.186.78, 142.250.184.206, 142.250.185.110, 142.250.186.163, 142.250.184.238, 142.250.186.142, 142.250.186.99, 23.199.214.10, 52.149.20.212, 150.171.27.10, 2.19.96.42, 4.175.87.197
            • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, g.bing.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: http://your@portal.investistratix.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):447
            Entropy (8bit):4.92758355357505
            Encrypted:false
            SSDEEP:12:BMQkuxRsTdO0sszLxeMLZQlLeLft9WRHeGHeAg:Wlux+49snxeWZyoft9el5g
            MD5:80A84C0A589501678A54BE33A972BB04
            SHA1:CA4E559C4CAB00D87D3A5ADE732C7481B26C1922
            SHA-256:4BCE352EED116A0E8BB6EDCF4FFBBBAC8BDC89D8A2D1BD08C3DB806BF7E54A71
            SHA-512:C1D332047339D68F74650E23E987BA4EB9138497902E1B0C30705148D625DB9E685EC795BFFCA2735CAE084260D3952449930E38E614B5888F1B6E38C4D61B53
            Malicious:false
            Reputation:low
            URL:https://portal.investistratix.com/?C=N;O=A
            Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">.<html>. <head>. <title>Index of /</title>. </head>. <body>.<h1>Index of /</h1>. <table>. <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</a></th><th><a href="?C=S;O=A">Size</a></th><th><a href="?C=D;O=A">Description</a></th></tr>. <tr><th colspan="5"><hr></th></tr>. <tr><th colspan="5"><hr></th></tr>.</table>.</body></html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):315
            Entropy (8bit):5.0572271090563765
            Encrypted:false
            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
            MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
            SHA1:A82190FC530C265AA40A045C21770D967F4767B8
            SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
            SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
            Malicious:false
            Reputation:low
            URL:https://portal.investistratix.com/favicon.ico
            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):447
            Entropy (8bit):4.92758355357505
            Encrypted:false
            SSDEEP:12:BMQkuxRsTdO0sszLxeMLZQlLeLft9WRHeGHeAg:Wlux+49snxeWZyoft9el5g
            MD5:80A84C0A589501678A54BE33A972BB04
            SHA1:CA4E559C4CAB00D87D3A5ADE732C7481B26C1922
            SHA-256:4BCE352EED116A0E8BB6EDCF4FFBBBAC8BDC89D8A2D1BD08C3DB806BF7E54A71
            SHA-512:C1D332047339D68F74650E23E987BA4EB9138497902E1B0C30705148D625DB9E685EC795BFFCA2735CAE084260D3952449930E38E614B5888F1B6E38C4D61B53
            Malicious:false
            Reputation:low
            URL:https://portal.investistratix.com/
            Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">.<html>. <head>. <title>Index of /</title>. </head>. <body>.<h1>Index of /</h1>. <table>. <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</a></th><th><a href="?C=S;O=A">Size</a></th><th><a href="?C=D;O=A">Description</a></th></tr>. <tr><th colspan="5"><hr></th></tr>. <tr><th colspan="5"><hr></th></tr>.</table>.</body></html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):447
            Entropy (8bit):4.929048927248548
            Encrypted:false
            SSDEEP:12:BMQkuxRsTdO0sszLxeJLZQlLeLft9WRHeGHeAg:Wlux+49snxeFZyoft9el5g
            MD5:4D457A87336B8F336C2B40C4C17E6641
            SHA1:7B5F64B368ACAC178471366E97BE3AEB92E37A51
            SHA-256:CB98B307D15D1A4A7678C51900D70AE974ED29D64EF3788D29477FBB955C71E2
            SHA-512:E427ECEAB992396746A47171512E62EC78ED89DE77B56031C06744D761A7457FF6C26969CE447415325F579C8D261587226279966282ADB82E3A186228C07C3D
            Malicious:false
            Reputation:low
            URL:https://portal.investistratix.com/?C=N;O=D
            Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">.<html>. <head>. <title>Index of /</title>. </head>. <body>.<h1>Index of /</h1>. <table>. <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=A">Name</a></th><th><a href="?C=M;O=A">Last modified</a></th><th><a href="?C=S;O=A">Size</a></th><th><a href="?C=D;O=A">Description</a></th></tr>. <tr><th colspan="5"><hr></th></tr>. <tr><th colspan="5"><hr></th></tr>.</table>.</body></html>.
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Mar 13, 2025 17:43:20.482311964 CET49672443192.168.2.5204.79.197.203
            Mar 13, 2025 17:43:25.294805050 CET49672443192.168.2.5204.79.197.203
            Mar 13, 2025 17:43:25.448781967 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:25.748012066 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:26.357450962 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:27.560478926 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:30.061631918 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:34.413733959 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:34.413759947 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:34.413917065 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:34.414299965 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:34.414313078 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:34.872936010 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:34.904196978 CET49672443192.168.2.5204.79.197.203
            Mar 13, 2025 17:43:35.460396051 CET4971780192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.460652113 CET4971880192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.465104103 CET8049717199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:35.465186119 CET4971780192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.465305090 CET8049718199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:35.465365887 CET4971880192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.492976904 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.493024111 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:35.493175983 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.493726015 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:35.493741989 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:36.186944008 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:36.187690020 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:36.187710047 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:36.189183950 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:36.189275980 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:36.190403938 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:36.190484047 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:36.234678984 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:36.234695911 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:36.281930923 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:37.074496031 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.075115919 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.075151920 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.076208115 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.076270103 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.085824966 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.086081982 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.093908072 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.093924999 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.139969110 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.581754923 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.581861019 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.581953049 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.582691908 CET49719443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.582715988 CET44349719199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.683878899 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.683926105 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:37.684089899 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.684479952 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:37.684495926 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.362631083 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.363311052 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:39.363342047 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.363723040 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.364322901 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:39.364392042 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.364742041 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:39.412317038 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.976653099 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.976723909 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:39.976789951 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:40.060462952 CET49720443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:40.060491085 CET44349720199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:42.693072081 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.693129063 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:42.693265915 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.693700075 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.693713903 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:42.712985992 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.713040113 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:42.713202953 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.713632107 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:42.713654995 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.326297045 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.326656103 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.326672077 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.327028036 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.328007936 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.328068972 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.328210115 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.372317076 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.476824045 CET49676443192.168.2.520.189.173.14
            Mar 13, 2025 17:43:44.506845951 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.552731037 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.630723000 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.630737066 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.631428003 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.638590097 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.638678074 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.685300112 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.815807104 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.816173077 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:44.816251993 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.817024946 CET49723443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:44.817055941 CET44349723199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:45.792627096 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:45.792731047 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:45.792771101 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:46.877125025 CET49715443192.168.2.5142.250.186.132
            Mar 13, 2025 17:43:46.877156973 CET44349715142.250.186.132192.168.2.5
            Mar 13, 2025 17:43:51.605557919 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:51.609436035 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:51.609471083 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:51.609656096 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:51.611255884 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:51.611268997 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:51.652321100 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:52.002186060 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:52.002274036 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:52.002335072 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:52.003875971 CET49724443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:52.003896952 CET44349724199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:53.182468891 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:53.182848930 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:53.182868004 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:53.183208942 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:53.183578014 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:43:53.183640957 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:43:53.233016968 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.528112888 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.528160095 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:00.529930115 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.530036926 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.531539917 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.531559944 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:00.576323986 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:00.924485922 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:00.924603939 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:00.924886942 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.925662041 CET49728443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:00.925712109 CET44349728199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:02.211169958 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:02.211575031 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:02.211601973 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:02.212001085 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:02.212435007 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:02.212519884 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:02.265537024 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:09.414963007 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:09.415007114 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:09.415085077 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:09.415653944 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:09.415671110 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:09.419044018 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:09.460333109 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:09.854623079 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:09.854707956 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:09.857568979 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:10.072285891 CET49729443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:10.072326899 CET44349729199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:11.020472050 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:11.020946026 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:11.020973921 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:11.021457911 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:11.021851063 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:11.021935940 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:11.076693058 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:13.753365993 CET49696443192.168.2.52.19.96.106
            Mar 13, 2025 17:44:14.139714003 CET4969880192.168.2.5142.250.186.35
            Mar 13, 2025 17:44:14.139844894 CET4969380192.168.2.5199.232.214.172
            Mar 13, 2025 17:44:14.139914036 CET4969580192.168.2.5199.232.214.172
            Mar 13, 2025 17:44:14.144651890 CET8049698142.250.186.35192.168.2.5
            Mar 13, 2025 17:44:14.144709110 CET4969880192.168.2.5142.250.186.35
            Mar 13, 2025 17:44:14.145143032 CET8049693199.232.214.172192.168.2.5
            Mar 13, 2025 17:44:14.145159960 CET8049695199.232.214.172192.168.2.5
            Mar 13, 2025 17:44:14.145184994 CET4969380192.168.2.5199.232.214.172
            Mar 13, 2025 17:44:14.145242929 CET4969580192.168.2.5199.232.214.172
            Mar 13, 2025 17:44:18.245990992 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.246042013 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:18.246139050 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.246503115 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.246517897 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:18.246860981 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.292325020 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:18.656694889 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:18.656785965 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:18.656887054 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.657620907 CET49730443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:18.657638073 CET44349730199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:19.804160118 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:19.804491043 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:19.804506063 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:19.804872036 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:19.805205107 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:19.805275917 CET44349731199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:19.858112097 CET49731443192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:20.467205048 CET4971780192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:20.467415094 CET4971880192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:20.472023964 CET8049717199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:20.472136021 CET8049718199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:34.468894005 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:34.468945026 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:34.469017982 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:34.469450951 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:34.469464064 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:36.330286026 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:36.330598116 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:36.330615044 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:36.331037045 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:36.331530094 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:36.331598997 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:36.373311043 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:36.880789995 CET4971880192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:36.880866051 CET4971780192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:36.885751963 CET8049718199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:36.885832071 CET4971880192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:36.886104107 CET8049717199.188.207.196192.168.2.5
            Mar 13, 2025 17:44:36.886157990 CET4971780192.168.2.5199.188.207.196
            Mar 13, 2025 17:44:45.934295893 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:45.934376955 CET44349735142.250.186.132192.168.2.5
            Mar 13, 2025 17:44:45.934433937 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:46.875266075 CET49735443192.168.2.5142.250.186.132
            Mar 13, 2025 17:44:46.875303030 CET44349735142.250.186.132192.168.2.5
            TimestampSource PortDest PortSource IPDest IP
            Mar 13, 2025 17:43:30.152009010 CET53588121.1.1.1192.168.2.5
            Mar 13, 2025 17:43:30.832302094 CET53600711.1.1.1192.168.2.5
            Mar 13, 2025 17:43:33.324657917 CET53615941.1.1.1192.168.2.5
            Mar 13, 2025 17:43:33.629939079 CET53606791.1.1.1192.168.2.5
            Mar 13, 2025 17:43:34.405611038 CET5846053192.168.2.51.1.1.1
            Mar 13, 2025 17:43:34.405781031 CET5262653192.168.2.51.1.1.1
            Mar 13, 2025 17:43:34.412477970 CET53584601.1.1.1192.168.2.5
            Mar 13, 2025 17:43:34.412677050 CET53526261.1.1.1192.168.2.5
            Mar 13, 2025 17:43:35.425391912 CET5727253192.168.2.51.1.1.1
            Mar 13, 2025 17:43:35.425743103 CET6332453192.168.2.51.1.1.1
            Mar 13, 2025 17:43:35.439975023 CET53633241.1.1.1192.168.2.5
            Mar 13, 2025 17:43:35.449450016 CET53572721.1.1.1192.168.2.5
            Mar 13, 2025 17:43:35.464176893 CET5455853192.168.2.51.1.1.1
            Mar 13, 2025 17:43:35.464524031 CET5822853192.168.2.51.1.1.1
            Mar 13, 2025 17:43:35.472935915 CET53545581.1.1.1192.168.2.5
            Mar 13, 2025 17:43:35.482034922 CET53582281.1.1.1192.168.2.5
            Mar 13, 2025 17:43:50.729250908 CET53543441.1.1.1192.168.2.5
            Mar 13, 2025 17:44:09.759927034 CET53528161.1.1.1192.168.2.5
            Mar 13, 2025 17:44:27.607743025 CET138138192.168.2.5192.168.2.255
            Mar 13, 2025 17:44:29.697429895 CET53540341.1.1.1192.168.2.5
            Mar 13, 2025 17:44:32.461019993 CET53559161.1.1.1192.168.2.5
            Mar 13, 2025 17:44:34.745810032 CET53610131.1.1.1192.168.2.5
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Mar 13, 2025 17:43:34.405611038 CET192.168.2.51.1.1.10x6a5aStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Mar 13, 2025 17:43:34.405781031 CET192.168.2.51.1.1.10x6462Standard query (0)www.google.com65IN (0x0001)false
            Mar 13, 2025 17:43:35.425391912 CET192.168.2.51.1.1.10x36b3Standard query (0)portal.investistratix.comA (IP address)IN (0x0001)false
            Mar 13, 2025 17:43:35.425743103 CET192.168.2.51.1.1.10x31deStandard query (0)portal.investistratix.com65IN (0x0001)false
            Mar 13, 2025 17:43:35.464176893 CET192.168.2.51.1.1.10x80b7Standard query (0)portal.investistratix.comA (IP address)IN (0x0001)false
            Mar 13, 2025 17:43:35.464524031 CET192.168.2.51.1.1.10x35c8Standard query (0)portal.investistratix.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Mar 13, 2025 17:43:34.412477970 CET1.1.1.1192.168.2.50x6a5aNo error (0)www.google.com142.250.186.132A (IP address)IN (0x0001)false
            Mar 13, 2025 17:43:34.412677050 CET1.1.1.1192.168.2.50x6462No error (0)www.google.com65IN (0x0001)false
            Mar 13, 2025 17:43:35.449450016 CET1.1.1.1192.168.2.50x36b3No error (0)portal.investistratix.com199.188.207.196A (IP address)IN (0x0001)false
            Mar 13, 2025 17:43:35.472935915 CET1.1.1.1192.168.2.50x80b7No error (0)portal.investistratix.com199.188.207.196A (IP address)IN (0x0001)false
            • portal.investistratix.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.549717199.188.207.196806716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 13, 2025 17:44:20.467205048 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.549718199.188.207.196806716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Mar 13, 2025 17:44:20.467415094 CET6OUTData Raw: 00
            Data Ascii:


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.549719199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:43:37 UTC675OUTGET / HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:43:37 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:43:37 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:43:37 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 44 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.549720199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:43:39 UTC613OUTGET /favicon.ico HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua-platform: "Windows"
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://portal.investistratix.com/
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:43:39 UTC164INHTTP/1.1 404 Not Found
            Date: Thu, 13 Mar 2025 16:43:39 GMT
            Server: Apache
            Content-Length: 315
            Connection: close
            Content-Type: text/html; charset=iso-8859-1
            2025-03-13 16:43:39 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.549723199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:43:44 UTC735OUTGET /?C=N;O=D HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://portal.investistratix.com/
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:43:44 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:43:44 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:43:44 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 41 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=A">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.549724199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:43:51 UTC743OUTGET /?C=N;O=A HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://portal.investistratix.com/?C=N;O=D
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:43:51 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:43:51 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:43:51 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 44 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            4192.168.2.549728199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:44:00 UTC743OUTGET /?C=N;O=D HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://portal.investistratix.com/?C=N;O=A
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:44:00 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:44:00 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:44:00 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 41 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=A">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            5192.168.2.549729199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:44:09 UTC743OUTGET /?C=N;O=A HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://portal.investistratix.com/?C=N;O=D
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:44:09 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:44:09 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:44:09 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 44 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            6192.168.2.549730199.188.207.1964436716C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-03-13 16:44:18 UTC743OUTGET /?C=N;O=D HTTP/1.1
            Host: portal.investistratix.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://portal.investistratix.com/?C=N;O=A
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-03-13 16:44:18 UTC190INHTTP/1.1 200 OK
            Date: Thu, 13 Mar 2025 16:44:18 GMT
            Server: Apache
            Vary: Accept-Encoding,User-Agent
            Content-Length: 447
            Connection: close
            Content-Type: text/html;charset=ISO-8859-1
            2025-03-13 16:44:18 UTC447INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 33 2e 32 20 46 69 6e 61 6c 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 0a 20 3c 68 65 61 64 3e 0a 20 20 3c 74 69 74 6c 65 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 74 69 74 6c 65 3e 0a 20 3c 2f 68 65 61 64 3e 0a 20 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 64 65 78 20 6f 66 20 2f 3c 2f 68 31 3e 0a 20 20 3c 74 61 62 6c 65 3e 0a 20 20 20 3c 74 72 3e 3c 74 68 20 76 61 6c 69 67 6e 3d 22 74 6f 70 22 3e 26 6e 62 73 70 3b 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4e 3b 4f 3d 41 22 3e 4e 61 6d 65 3c 2f 61 3e 3c 2f 74 68 3e 3c 74 68 3e 3c 61 20 68 72 65 66 3d 22 3f 43 3d 4d 3b 4f 3d 41 22 3e 4c 61 73 74 20 6d 6f 64 69 66 69 65 64 3c 2f
            Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"><html> <head> <title>Index of /</title> </head> <body><h1>Index of /</h1> <table> <tr><th valign="top">&nbsp;</th><th><a href="?C=N;O=A">Name</a></th><th><a href="?C=M;O=A">Last modified</


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:12:43:23
            Start date:13/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff7b45a0000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:12:43:28
            Start date:13/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2056 /prefetch:3
            Imagebase:0x7ff7b45a0000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:8
            Start time:12:43:31
            Start date:13/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,5387368228543419576,16882787452952942304,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3288 /prefetch:8
            Imagebase:0x7ff7b45a0000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:11
            Start time:12:43:34
            Start date:13/03/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://your@portal.investistratix.com"
            Imagebase:0x7ff7b45a0000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly