Windows Analysis Report
hard money loans.js


General Information

Sample name: hard money loans.js
Analysis ID: 1437717
MD5: 095cc7705d7ee484b60fd514bc2cc0de
SHA1: a1cee6ca7f4ec52ab66b4ca169a010c677b7a79f
SHA256: c2d7f079c17087aa2ccba1ee2e673fb5a56702f7abf79b09512bc59e6992fc72


Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%


Sigma detected: WScript or CScript Dropper
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory


Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: Joe Sandbox View IP Address:
Source: Joe Sandbox View IP Address:
Source: Joe Sandbox View IP Address:
Source: Joe Sandbox View IP Address:
Source: Joe Sandbox View IP Address:
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=U1+144COeZ1TFcd&MD=6gZ3LCt7 HTTP/1.1
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1 Host: Connection: keep-alive Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_promos HTTP/1.1 Host: Connection: keep-alive Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_0 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCLnKzQEIitPNAQjB1M0BCLrYzQEY9snNARjrjaUX Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=7&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=h&oit=1&cp=1&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A&oit=4&cp=6&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F&oit=4&cp=7&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2F&oit=4&cp=8&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Fa&oit=3&cp=9&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Fay&oit=3&cp=10&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Fayn&oit=3&cp=11&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Fayna&oit=3&cp=12&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Faynasy&oit=3&cp=14&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Faynasy.c&oit=3&cp=16&pgcl=7&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t& HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t& HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET / HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /wp-includes/js/wp-emoji-release.min.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/pj-news-ticker/public/css/pj-news-ticker.css?ver=1.1.1 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-includes/css/dist/block-library/style.min.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/css/base.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/css/flexslider.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/panel/components/fontawesome/css/font-awesome.min.css?ver=4.7.0 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/css/mmenu.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/css/prettyPhoto.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/style.css?ver=1.9.2 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/colors/default.css?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery.js?ver=1.12.4-wp HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/pj-news-ticker/public/js/pj-news-ticker.js?ver=1.1.1 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/panel/scripts/modernizr-2.6.2.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2017/08/ayna-logo-with-slogan-for-aynasy-website-300x116.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/qtranslate-x/flags/gb.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=U1+144COeZ1TFcd&MD=6gZ3LCt7 HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33 Host:
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/panel/components/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: font Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2017/08/banner2-1388x550.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/qtranslate-x/flags/sy.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/TTT-750x900.jpeg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=3.3.3 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.70 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=3.3.3 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=3.3.3 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-includes/js/comment-reply.min.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/superfish.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/jquery.flexslider.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/jquery.mmenu.min.all.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/panel/scripts/jquery.fitvids.js?ver=1.1 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/jquery.isotope.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/jquery.prettyPhoto.min.js?ver=3.1.6 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/js/scripts.js?ver=1.9.2 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/themes/business3ree/panel/components/retinajs/dist/retina.js?ver=1.3.0 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-includes/js/wp-embed.min.js?ver=5.3.17 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/TTT2-750x900.jpeg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2017/07/erp.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /google_ads.html?html=Test&delay=3 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Accept: text/html, */*; q=0.01 X-Requested-With: XMLHttpRequest sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/Ayna_Places2.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/Ayna_Places-560x996.jpeg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/restaurant.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2018/03/E-Market.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2014/08/Slider_Image_1-1920x550.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2014/06/ayna-building-outside-for-site2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: qtrans_front_language=en
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=w&oit=1&cp=1&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=ww&oit=1&cp=2&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www&oit=1&cp=3&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.&oit=1&cp=4&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.n&oit=1&cp=5&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t& HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nil&oit=1&cp=7&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nils&oit=1&cp=8&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsp&oit=1&cp=9&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nils&oit=1&cp=8&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsj&oit=1&cp=9&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsjap&oit=1&cp=11&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsjapa&oit=1&cp=12&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsjapan&oit=1&cp=13&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=www.nilsjapan.&oit=1&cp=14&pgcl=4&gs_rn=42&psi=562LCbEIUpWHuN35&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t& HTTP/1.1 Host: Connection: keep-alive X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIkcrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc= Sec-Fetch-Site: none Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: empty User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET / HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /common/css/html5reset-1.6.1.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/css/common220511.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /css/top220511.css?20220527 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/css/res220511.css?20220527 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /srce_rsslib.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/logo.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /flags/USA.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /flags/Japan.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /flags/KoreaSouth.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /flags/China.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/slider1.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-1.8.3.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/animate.css/3.2.0/animate.min.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/mark.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/pagetop.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/reason_img01.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/icon_slider.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/pagetop_text.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/slider2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/bg_header.gif HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/img_short_term2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/reason_img02.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/reason_img03.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/js/common220511.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/magnific-popup.js/1.1.0/jquery.magnific-popup.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/js/jquery.heightLine.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/js/animatedModal.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /css/magnific-popup.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ja_JP/sdk.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/js/common2-220511.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /swiper/swiper-bundle.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/css/swiper-bundle.min.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /srce_rsslib190717.js?20190718 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/top/img_fulltime2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/kai.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ja_JP/sdk.js?hash=ef40b4a9af1c1bccaaaf6b59e3c76456 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /swiper@11.1.1/swiper-bundle.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/barbier-bastien.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/alexander-ray.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/eric-truong.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/gloria-kim.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /schoolactivity/?feed=rss2 HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /news/?feed=rss2 HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /fukuoka-times/feed/ HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /interview/img/btn14.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513
Source: global traffic HTTP traffic detected: GET /interview/img/btn13.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513
Source: global traffic HTTP traffic detected: GET /interview/img/btn12.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513
Source: global traffic HTTP traffic detected: GET /tag/9r53tk7i3z?ref=gtm HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /interview/img/btn11.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513
Source: global traffic HTTP traffic detected: GET /interview/img/btn10.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /img/top/icon_intro1.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /td/ga/rul?tid=G-LD4SYW17KG&gacid=1053100559.1715107514&gtm=45je4510v875046350z8812089807za200&dma=0&gcd=13l3l3l3l1&npa=0&pscdl=noapi&aip=1&fledge=1&z=463450891 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCLnKzQEIitPNAQjB1M0BCLrYzQEY9snNARjrjaUX Sec-Fetch-Site: cross-site Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /s/0.7.32/clarity.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: CLID=ba39416833fe47cdaf73f4d02c0ae363.20240507.20250507
Source: global traffic HTTP traffic detected: GET /img/top/intro_img1.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /img/top/icon_intro2.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /img/top/intro_img2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /img/top/icon_intro3.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j101&tid=UA-3973887-1&cid=1053100559.1715107514&jid=800801805&_u=YEBAAEAAAAAAACAAI~&z=830192285 HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCLnKzQEIitPNAQjB1M0BCLrYzQEY9snNARjrjaUX Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: NID=514=pxi0geu4mE6TN0e-Ez7QI_Hi9nLigiCYIYRUGPu5nU1j81gRAROsZ4MKSEjWw0_DqOrhL8g-5bMvGTlyTMChZifVQlIqaM8dyaXKxut32yQNXcUk3Ccyon6ZAoabsUbKBYglvIjYBB73wK9xjCfNdPABytREAU3avvLBsL7AYxQ
Source: global traffic HTTP traffic detected: GET /common/img/line.gif HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/gnav_modal_arrow_390.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/icon_gnav_moda.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /img/top/intro_img3.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /common/img/ft_bnr_fukuoka.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/ft_bnr_katakana.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/ft_bnr_kanji.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/ft_bnr_news_vocabulary.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/bnr_instagram.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/ft_logo.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /img/top/icon_point.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /img/top/bg_lp220511.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /img/top/icon_title.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /img/top/icon_star_blue.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /common/img/icon_menu_o.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588
Source: global traffic HTTP traffic detected: GET /v2.8/plugins/page.php?adapt_container_width=true&app_id=& HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/y5/l/0,ja_JP/d3P2iocFUTK.css?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yn/r/tT656QlGoSx.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yr/r/xjg1QNQguf-.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yC/r/O9zq51FKpXz.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yX/r/qnn7MVQZYOT.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yn/r/qwSlV7K_jlE.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /v/t39.30808-6/327187306_3286831278313605_6695552522928692740_n.png?stp=dst-png_s261x260&_nc_cat=105&ccb=1-7&_nc_sid=5f2048&_nc_ohc=_cRvxPnp1ScQ7kNvgFDLrF3&_nc_ht=scontent-ord5-2.xx&edm=AOUVRTIEAAAA&oh=00_AfC941fym--yxB_FvLMXMXvOUKlBZWcd3XCeL058eUTldQ&oe=6640573E HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yF/r/p55HfXW__mM.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3iLxq4/yM/l/ja_JP/btW70syVT6v.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3irB34/yo/l/ja_JP/zYzGplAqD4J.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /v/t39.30808-1/327199643_3163699497261653_3851852910090655702_n.jpg?stp=cp0_dst-jpg_p50x50&_nc_cat=109&ccb=1-7&_nc_sid=5f2048&_nc_ohc=ZOLUGC2DXeIQ7kNvgHlyf9S&_nc_ht=scontent-ord5-1.xx&edm=AOUVRTIEAAAA&oh=00_AfDu5kykS-JF0HTgNhL10GlZAOEm2bamyjg4YJXCBlOPRQ&oe=6640361A HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yw/r/UXtr_j2Fwe-.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer:,ja_JP/d3P2iocFUTK.css?_nc_x=Ij3Wp8lg5Kz Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yU/r/B4AwfKlNLSX.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yv/r/4Za9TE_Wiy4.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /platform/plugin/tab/renderer/?key=timeline& HTTP/1.1 Host: Connection: keep-alive X-FB-LSD: _P7CTlHeqYd8jQ5N18UMzL sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" X-ASBD-ID: 129477 sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yH/r/xgVgalBG80z.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer:,ja_JP/d3P2iocFUTK.css?_nc_x=Ij3Wp8lg5Kz Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;
Source: global traffic HTTP traffic detected: GET /rsrc.php/v3/yH/r/ieeHDjcGsIR.js?_nc_x=Ij3Wp8lg5Kz HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" Origin: sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /login/? HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/gnav_modal_arrow_450.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga_LD4SYW17KG=GS1.1.1715107514.1.0.1715107514.60.0.0; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;
Source: global traffic HTTP traffic detected: GET /programs/ HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /common/css/contents220511.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /programs/page.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/css/res220511.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/css/res_lower.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _ga=GA1.1.1053100559.1715107514; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /certificate-issuance/_img/bannar.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0; _ga=GA1.2.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /programs/img/2016/fulltime.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0; _ga=GA1.2.1053100559.1715107514
Source: global traffic HTTP traffic detected: GET /tag/9r53tk7i3z?ref=gtm HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: CLID=ba39416833fe47cdaf73f4d02c0ae363.20240507.20250507; MUID=1C80808FB8D6656620C494F7B9956433
Source: global traffic HTTP traffic detected: GET /common/img/bg_h1.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/side_line.gif HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/icon_side.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/bg_h2.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/side_ttl.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/js/common2_lower.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /programs/img/2016/short.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /programs/img/2016/icon03.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /programs/img/2016/icon04.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /programs/img/2016/icon05.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/side_flag.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/under_contact_bg.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /v2.8/plugins/page.php?adapt_container_width=true&app_id=& HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/icon_mail.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0
Source: global traffic HTTP traffic detected: GET /common/img/under_contact_bg_res_on.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/under_contact_bg_res_small_on.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/under_contact_bg2_res_on.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/under_contact_bg2_res_small_on.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107532.42.0.0;
Source: global traffic HTTP traffic detected: GET /platform/plugin/tab/renderer/?key=timeline& HTTP/1.1 Host: Connection: keep-alive X-FB-LSD: VZjwWMRErGQqV5oKfNxZQ2 sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" X-ASBD-ID: 129477 sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /login/? HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /programs/intensive12-b/ HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: GET /programs/intensive12-b/page.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /programs/programs.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514;; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /scroll-hint@latest/js/scroll-hint.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scroll-hint@latest/css/scroll-hint.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/js/jquery.bxslider2015.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /programs/intensive12-b/img/img.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min01.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min02.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /tag/9r53tk7i3z?ref=gtm HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: CLID=ba39416833fe47cdaf73f4d02c0ae363.20240507.20250507; MUID=1C80808FB8D6656620C494F7B9956433
Source: global traffic HTTP traffic detected: GET /common/img/activity/min04.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/bg_photowrap.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /scroll-hint@1.2.5/js/scroll-hint.min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/icon_checkmark.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/js/jquery.colorbox-min.js HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: script Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/css/colorbox.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/css/jquery.bxslider2015.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min05.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /scroll-hint@1.2.5/css/scroll-hint.css HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: text/css,*/*;q=0.1 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: style Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/activity/min06.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min07.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min12.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min11.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min13.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /v2.8/plugins/page.php?adapt_container_width=true&app_id=& HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: cross-site Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/img/activity/min14.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588;; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0
Source: global traffic HTTP traffic detected: GET /common/img/activity/min15.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/activity/min16.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/activity/min17.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/activity/min18.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/activity/min19.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/activity/min20.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_maintext.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_grammar.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_reading.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_vocabulary.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /platform/plugin/tab/renderer/?key=timeline& HTTP/1.1 Host: Connection: keep-alive X-FB-LSD: up8vi0in-qA0hKDgkgU8v6 sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" X-ASBD-ID: 129477 sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: */* Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /programs/img/icon_listening.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_current.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_step1.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_step3.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_step4.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_step5.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /login/? HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: navigate Sec-Fetch-Dest: iframe Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /programs/img/bg_note.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_checkmark.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/bg_table.jpg HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /programs/img/icon_step_arrow.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/download_btn1.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/download_btn2.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/images/bx_loader.gif HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
Source: global traffic HTTP traffic detected: GET /common/img/images/controls.png HTTP/1.1 Host: Connection: keep-alive sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117" sec-ch-ua-mobile: ?0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36 sec-ch-ua-platform: "Windows" Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Cookie: _gcl_au=1.1.101556377.1715107513; _gid=GA1.2.1273797957.1715107514; _gat_UA-3973887-1=1; _clck=1p7kc8m%7C2%7Cflk%7C0%7C1588; _ga=GA1.1.1053100559.1715107514; _ga_LD4SYW17KG=GS1.1.1715107514.1.1.1715107541.33.0.0;
String found in binary or memory: <a class="popup-iframe" href="//"> equals (Youtube)
Source: chromecache_234.8.dr String found in binary or memory: <a class="popup-iframe" href="//"> equals (Youtube)
Source: chromecache_234.8.dr String found in binary or memory: <a class="popup-iframe" href="//"> equals (Youtube)
Source: chromecache_234.8.dr String found in binary or memory: <a class="popup-iframe" href="//"><figure><img src="img/img_movie01.jpg" alt="About NILS" class="over"></figure></a> equals (Youtube)
String found in binary or memory: <div class="facebook"><a href="" target="_blank"><span>Facebook</span></a></div> equals (Facebook)
Source: chromecache_234.8.dr String found in binary or memory: <div class="fb-page" data-href="" data-tabs="timeline" data-width="250" data-height="250" data-small-header="true" data-adapt-container-width="true" data-hide-cover="false" data-show-facepile="true"><blockquote cite="" class="fb-xfbml-parse-ignore"><a href="">ALL Japanese speakers! Learn Japanese Language at NILS</a></blockquote></div> equals (Facebook)
Source: chromecache_419.8.dr String found in binary or memory: * License: equals (Facebook)
Source: chromecache_419.8.dr String found in binary or memory: * License: equals (Facebook)
Source: chromecache_252.8.dr String found in binary or memory: * License: equals (Facebook)
Source: chromecache_440.8.dr String found in binary or memory: * License: equals (Facebook)
Source: chromecache_407.8.dr String found in binary or memory: * License: equals (Facebook)
Source: chromecache_374.8.dr String found in binary or memory: <p><a href=""><img decoding="async" loading="lazy" class="alignleft wp-image-3462" src="" alt="" width="70" height="70" /></a><a href=""><img decoding="async" loading="lazy" class="alignleft wp-image-3465" src="" alt="" width="70" height="70" /></a></p> equals (Facebook)
Math.round(p);v["gtm.videoCurrentTime"]=Math.round(q);v["gtm.videoElapsedTime"]=Math.round(f);v["gtm.videoPercent"]=r;v["gtm.videoVisible"]=t;return v},Wj:function(){e=zb()},sd:function(){d()}}};var dc=ka(["data-gtm-yt-inspected-"]),AC=["",""],BC,CC=!1; equals (Youtube)
Source: chromecache_385.8.dr String found in binary or memory: ["https:",["https //","https // live","https // login","https //","https // login","https // join","https // unblocked","https // join","",""],["","","","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:suggestrelevance":[601,600,555,554,553,552,551,550,401,400],"google:suggestsubtypes":[[512,433,131],[512],[512],[512],[512,433,131],[512,433],[512],[512],[44],[44]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","NAVIGATION","NAVIGATION"],"google:verbatimrelevance":851}] equals (Facebook)
Source: chromecache_311.8.dr String found in binary or memory: c?"runIfCanceled":"runIfUncanceled",[]);if(!g.length)return!0;var h=iA(a,c,e);P(121);if(""===h["gtm.elementUrl"])return P(122),!0;if(d&&f){for(var m=Jb(b,g.length),n=0;n<g.length;++n)g[n](h,m);return m.done}for(var p=0;p<g.length;++p)g[p](h,function(){});return!0},lA=function(){var a=[],b=function(c){return pb(a,function(d){return d.form===c})};return{store:function(c,d){var e=b(c);e?e.button=d:a.push({form:c,button:d})},get:function(c){var d=b(c);return d?d.button:null}}}, equals (Facebook)
Source: chromecache_311.8.dr String found in binary or memory: e||f||g.length||h.length))return;var n={Xg:d,Vg:e,Wg:f,Kh:g,Lh:h,ye:m,zb:b},p=G.YT,q=function(){IC(n)};if(p)return p.ready&&p.ready(q),b;var r=G.onYouTubeIframeAPIReady;G.onYouTubeIframeAPIReady=function(){r&&r();q()};I(function(){for(var t=H.getElementsByTagName("script"),u=t.length,v=0;v<u;v++){var w=t[v].getAttribute("src");if(LC(w,"iframe_api")||LC(w,"player_api"))return b}for(var x=H.getElementsByTagName("iframe"),y=x.length,B=0;B<y;B++)if(!CC&&JC(x[B], sc(""), equals (Youtube)
Source: chromecache_248.8.dr String found in binary or memory: return b}yC.K="internal.enableAutoEventOnTimer";var dc=ka(["data-gtm-yt-inspected-"]),AC=["",""],BC,CC=!1; equals (Youtube)
Source: chromecache_311.8.dr String found in binary or memory: var NB=function(a,b,c,d,e){var f=Jz("fsl",c?"nv.mwt":"mwt",0),g;g=c?Jz("fsl","nv.ids",[]):Jz("fsl","ids",[]);if(!g.length)return!0;var h=Fz(a,"gtm.formSubmit",g),m=a.action;m&&m.tagName&&(m=a.cloneNode(!1).action);P(121);if(""===m)return P(122),!0;h["gtm.elementUrl"]=m;h["gtm.formCanceled"]=c;null!=a.getAttribute("name")&&(h["gtm.interactedFormName"]=a.getAttribute("name"));e&&(h["gtm.formSubmitElement"]=e,h["gtm.formSubmitElementText"]=e.value);if(d&&f){if(!uy(h,vy(b, equals (Facebook)
Source: chromecache_407.8.dr String found in binary or memory: window.FB&&window.FB.__buffer&&(window.__buffer=babelHelpers["extends"]({},window.FB.__buffer)); } }).call(global);})();} catch (e) {var i = new Image();i.crossOrigin = 'anonymous';i.dataset.testid = 'fbSDKErrorReport';i.src=''+encodeURIComponent('{"error":"LOAD", "extra": {"name":"''","line":"'+(e.lineNumber||e.line)+'","script":"'+(e.fileName||e.sourceURL||e.script||"sdk.js")+'","stack":"'+(e.stackTrace||e.stack)+'","revision":"1013322639","namespace":"FB","message":"'+e.message+'"}}');document.body.appendChild(i);} equals (Facebook)
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: unknown HTTP traffic detected: POST /log?format=json&hasfast=true HTTP/1.1 Host:
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not Found Date: Tue, 07 May 2024 18:44:38 GMT Server: Apache
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2

System Summary

Source: C:\Windows\System32\wscript.exe COM Object queried: Shell Automation Service HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13709620-C279-11CE-A49E-444553540000} Jump to behavior
Source: hard money loans.js Initial sample: Strings found which are bigger than 50
Source: classification engine Classification label: mal48.winJS@40/490@52/22
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7316:120:WilError_03
Source: C:\Windows\System32\wscript.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\System32\wscript.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\hard money loans.js"
Source: unknown Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\hard money loans.js"
Source: unknown Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\hard money loans.js"
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2084,i,3319928351809563255,12913828704732883118,262144 /prefetch:8
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\cscript.exe "C:\Windows\System32\cscript.exe" "hard money loans.js"
Source: C:\Windows\System32\cscript.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\cscript.exe "C:\Windows\System32\cscript.exe" "hard money loans.js" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2084,i,3319928351809563255,12913828704732883118,262144 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: jscript.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: scrobj.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: jscript.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: scrobj.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: version.dll
Source: C:\Windows\System32\wscript.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\wscript.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\wscript.exe Section loaded: sxs.dll
Source: C:\Windows\System32\wscript.exe Section loaded: jscript.dll
Source: C:\Windows\System32\wscript.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\wscript.exe Section loaded: amsi.dll
Source: C:\Windows\System32\wscript.exe Section loaded: userenv.dll
Source: C:\Windows\System32\wscript.exe Section loaded: profapi.dll
Source: C:\Windows\System32\wscript.exe Section loaded: wldp.dll
Source: C:\Windows\System32\wscript.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\wscript.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\wscript.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\wscript.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\wscript.exe Section loaded: msisip.dll
Source: C:\Windows\System32\wscript.exe Section loaded: wshext.dll
Source: C:\Windows\System32\wscript.exe Section loaded: scrobj.dll
Source: C:\Windows\System32\wscript.exe Section loaded:
Source: C:\Windows\System32\cscript.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: jscript.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\cscript.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32 Jump to behavior
Source: Google Drive.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.6.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: hard money loans.js Static file information: File size 48627210 > 1048576
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Window found: window name: WSH-Timer Jump to behavior
Source: C:\Windows\System32\wscript.exe Window found: window name: WSH-Timer Jump to behavior
Source: C:\Windows\System32\wscript.exe Window found: window name: WSH-Timer
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\cscript.exe "C:\Windows\System32\cscript.exe" "hard money loans.js" Jump to behavior
Source: C:\Windows\System32\wscript.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs