Edit tour

Windows Analysis Report
https://shorturl.at/sJMQX

Overview

General Information

Sample URL:https://shorturl.at/sJMQX
Analysis ID:1310165
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6032 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://shorturl.at/sJMQX MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 1756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1760,i,17764110904755911021,4306917296346461542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /sJMQX HTTP/1.1Host: shorturl.atConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sJMQX HTTP/1.1Host: www.shorturl.atConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: shorturl.at
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: clean0.win@26/0@12/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://shorturl.at/sJMQX
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1760,i,17764110904755911021,4306917296346461542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1760,i,17764110904755911021,4306917296346461542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1310165 URL: https://shorturl.at/sJMQX Startdate: 18/09/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        dnsIp3 11 192.168.2.1 unknown unknown 5->11 13 239.255.255.250 unknown Reserved 5->13 8 chrome.exe 5->8         started        process4 dnsIp5 15 accounts.google.com 142.250.80.109, 443, 49711 GOOGLEUS United States 8->15 17 clients.l.google.com 142.250.80.110, 443, 49708 GOOGLEUS United States 8->17 19 6 other IPs or domains 8->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://shorturl.at/sJMQX0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.80.109
truefalse
    high
    www.shorturl.at
    172.67.143.86
    truefalse
      high
      shorturl.at
      104.21.95.58
      truefalse
        high
        www.google.com
        142.251.40.164
        truefalse
          high
          clients.l.google.com
          142.250.80.110
          truefalse
            high
            clients2.google.com
            unknown
            unknownfalse
              high
              veri.luna5sun.ru.com
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://www.shorturl.at/sJMQXfalse
                  high
                  https://shorturl.at/sJMQXfalse
                    high
                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                      high
                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        239.255.255.250
                        unknownReserved
                        unknownunknownfalse
                        142.250.80.110
                        clients.l.google.comUnited States
                        15169GOOGLEUSfalse
                        172.217.165.132
                        unknownUnited States
                        15169GOOGLEUSfalse
                        142.250.80.109
                        accounts.google.comUnited States
                        15169GOOGLEUSfalse
                        172.67.143.86
                        www.shorturl.atUnited States
                        13335CLOUDFLARENETUSfalse
                        104.21.95.58
                        shorturl.atUnited States
                        13335CLOUDFLARENETUSfalse
                        IP
                        192.168.2.1
                        Joe Sandbox Version:38.0.0 Beryl
                        Analysis ID:1310165
                        Start date and time:2023-09-18 17:34:11 +02:00
                        Joe Sandbox Product:CloudBasic
                        Overall analysis duration:0h 3m 42s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                        Sample URL:https://shorturl.at/sJMQX
                        Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                        Number of analysed new started processes analysed:6
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Detection:CLEAN
                        Classification:clean0.win@26/0@12/7
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 0
                        • Number of non-executed functions: 0
                        • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 142.250.80.35, 34.104.35.123, 142.251.40.227
                        • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                        • Not all processes where analyzed, report is missing behavior information
                        • VT rate limit hit for: https://shorturl.at/sJMQX
                        No simulations
                        No created / dropped files found
                        No static file info

                        Download Network PCAP: filteredfull

                        • Total Packets: 76
                        • 443 (HTTPS)
                        • 53 (DNS)
                        TimestampSource PortDest PortSource IPDest IP
                        Sep 18, 2023 17:34:37.645415068 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:37.645495892 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.645628929 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:37.646332979 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:37.646370888 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.646615028 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:37.646713972 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:37.646833897 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:37.647021055 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:37.647047997 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:37.949786901 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:37.950360060 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:37.950393915 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:37.952789068 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:37.952908039 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:37.963135958 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.963572979 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:37.963612080 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.964426994 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.964550018 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:37.965842009 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:37.965960979 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.123840094 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.123910904 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.124033928 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.124521017 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.124553919 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.235491037 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.235882044 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:38.236042976 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.236206055 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.236438036 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:38.236634970 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.236676931 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:38.277204990 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.277218103 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.277239084 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:38.318295956 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.334377050 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.335057020 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.335093021 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.336359978 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.336607933 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.341821909 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.342025042 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.342422009 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.342441082 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.355664968 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:38.356075048 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:38.356271982 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.357286930 CEST49708443192.168.2.3142.250.80.110
                        Sep 18, 2023 17:34:38.357326031 CEST44349708142.250.80.110192.168.2.3
                        Sep 18, 2023 17:34:38.377283096 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:38.377579927 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:38.377707005 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.379657984 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.379690886 CEST44349709104.21.95.58192.168.2.3
                        Sep 18, 2023 17:34:38.379719019 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.379782915 CEST49709443192.168.2.3104.21.95.58
                        Sep 18, 2023 17:34:38.382102966 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.483647108 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.483727932 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.483978033 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.484375954 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.484415054 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.543493986 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.543642044 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.543672085 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.543847084 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.543940067 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.544478893 CEST49711443192.168.2.3142.250.80.109
                        Sep 18, 2023 17:34:38.544502974 CEST44349711142.250.80.109192.168.2.3
                        Sep 18, 2023 17:34:38.695554972 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.695992947 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.696043968 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.697308064 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.697470903 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.699328899 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.699435949 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.699520111 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.739147902 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.739190102 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.780206919 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.961970091 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.962145090 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:38.962315083 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.963486910 CEST49712443192.168.2.3172.67.143.86
                        Sep 18, 2023 17:34:38.963521004 CEST44349712172.67.143.86192.168.2.3
                        Sep 18, 2023 17:34:41.900605917 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:41.900684118 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:41.900774956 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:41.901062965 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:41.901087999 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.101721048 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.102189064 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:42.102215052 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.103430033 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.103516102 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:42.306972027 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:42.307403088 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.347481966 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:42.347527981 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:42.387511015 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:52.099096060 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:52.099251032 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:34:52.099436998 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:52.442308903 CEST49716443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:34:52.442358017 CEST44349716172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.735492945 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:41.735563040 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.735742092 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:41.737572908 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:41.737620115 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.941279888 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.942519903 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:41.942569971 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.943456888 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.944770098 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:41.944981098 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:41.984497070 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:51.929235935 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:51.929331064 CEST44349719172.217.165.132192.168.2.3
                        Sep 18, 2023 17:35:51.929577112 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:53.447068930 CEST49719443192.168.2.3172.217.165.132
                        Sep 18, 2023 17:35:53.447140932 CEST44349719172.217.165.132192.168.2.3
                        TimestampSource PortDest PortSource IPDest IP
                        Sep 18, 2023 17:34:37.501362085 CEST6439853192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:37.507050991 CEST6317253192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:37.593915939 CEST53643981.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:37.598601103 CEST53631721.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:38.029799938 CEST4929453192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:38.121881962 CEST53492941.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:38.387006998 CEST5975253192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:38.482091904 CEST53597521.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:38.968246937 CEST5958653192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:39.218342066 CEST53595861.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:40.288273096 CEST5185753192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:40.737489939 CEST53518571.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:41.685801983 CEST5118153192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:41.777153015 CEST53511811.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:41.784111023 CEST4917553192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:41.874892950 CEST53491751.1.1.1192.168.2.3
                        Sep 18, 2023 17:34:45.760755062 CEST5995153192.168.2.31.1.1.1
                        Sep 18, 2023 17:34:46.771044970 CEST5995153192.168.2.39.9.9.9
                        Sep 18, 2023 17:34:46.989521980 CEST53599519.9.9.9192.168.2.3
                        Sep 18, 2023 17:35:32.707390070 CEST5148653192.168.2.31.1.1.1
                        Sep 18, 2023 17:35:33.312256098 CEST53514861.1.1.1192.168.2.3
                        Sep 18, 2023 17:36:33.364418983 CEST5404353192.168.2.31.1.1.1
                        Sep 18, 2023 17:36:33.785665035 CEST53540431.1.1.1192.168.2.3
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Sep 18, 2023 17:34:37.501362085 CEST192.168.2.31.1.1.10x3cf5Standard query (0)shorturl.atA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:37.507050991 CEST192.168.2.31.1.1.10xfe56Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.029799938 CEST192.168.2.31.1.1.10xefe4Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.387006998 CEST192.168.2.31.1.1.10x3cd2Standard query (0)www.shorturl.atA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.968246937 CEST192.168.2.31.1.1.10x8c0cStandard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:40.288273096 CEST192.168.2.31.1.1.10x9070Standard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:41.685801983 CEST192.168.2.31.1.1.10xaa86Standard query (0)www.google.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:41.784111023 CEST192.168.2.31.1.1.10x93dbStandard query (0)www.google.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:45.760755062 CEST192.168.2.31.1.1.10xead8Standard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:46.771044970 CEST192.168.2.39.9.9.90xead8Standard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:35:32.707390070 CEST192.168.2.31.1.1.10x9581Standard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:36:33.364418983 CEST192.168.2.31.1.1.10x2c9eStandard query (0)veri.luna5sun.ru.comA (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Sep 18, 2023 17:34:37.593915939 CEST1.1.1.1192.168.2.30x3cf5No error (0)shorturl.at104.21.95.58A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:37.593915939 CEST1.1.1.1192.168.2.30x3cf5No error (0)shorturl.at172.67.143.86A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:37.598601103 CEST1.1.1.1192.168.2.30xfe56No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                        Sep 18, 2023 17:34:37.598601103 CEST1.1.1.1192.168.2.30xfe56No error (0)clients.l.google.com142.250.80.110A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.121881962 CEST1.1.1.1192.168.2.30xefe4No error (0)accounts.google.com142.250.80.109A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.482091904 CEST1.1.1.1192.168.2.30x3cd2No error (0)www.shorturl.at172.67.143.86A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:38.482091904 CEST1.1.1.1192.168.2.30x3cd2No error (0)www.shorturl.at104.21.95.58A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:39.218342066 CEST1.1.1.1192.168.2.30x8c0cName error (3)veri.luna5sun.ru.comnonenoneA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:40.737489939 CEST1.1.1.1192.168.2.30x9070Name error (3)veri.luna5sun.ru.comnonenoneA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:41.777153015 CEST1.1.1.1192.168.2.30xaa86No error (0)www.google.com142.251.40.164A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:41.874892950 CEST1.1.1.1192.168.2.30x93dbNo error (0)www.google.com172.217.165.132A (IP address)IN (0x0001)false
                        Sep 18, 2023 17:34:46.989521980 CEST9.9.9.9192.168.2.30xead8Name error (3)veri.luna5sun.ru.comnonenoneA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:35:33.312256098 CEST1.1.1.1192.168.2.30x9581Name error (3)veri.luna5sun.ru.comnonenoneA (IP address)IN (0x0001)false
                        Sep 18, 2023 17:36:33.785665035 CEST1.1.1.1192.168.2.30x2c9eName error (3)veri.luna5sun.ru.comnonenoneA (IP address)IN (0x0001)false
                        • shorturl.at
                        • clients2.google.com
                        • accounts.google.com
                        • www.shorturl.at
                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        0192.168.2.349709104.21.95.58443C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampkBytes transferredDirectionData
                        2023-09-18 15:34:38 UTC0OUTGET /sJMQX HTTP/1.1
                        Host: shorturl.at
                        Connection: keep-alive
                        sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2023-09-18 15:34:38 UTC3INHTTP/1.1 301 Moved Permanently
                        Date: Mon, 18 Sep 2023 15:34:38 GMT
                        Content-Type: text/html; charset=iso-8859-1
                        Transfer-Encoding: chunked
                        Connection: close
                        location: https://www.shorturl.at/sJMQX
                        x-xss-protection: 1; mode=block
                        x-content-type-options: nosniff
                        x-nginx-upstream-cache-status: MISS
                        x-server-powered-by: Engintron
                        CF-Cache-Status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=BEGfQaRk7wHMw0Nq6lxOV8w1bsNrn%2BT6YXHUeAGSecBx3D11WtA3R%2Fj6d5Qk3DsFDT9fNi82cNpDgKlTC8SdtbdnWX1v6KCg%2B9zB4Qr0rIxHq1Z3aGKyzGNDvYSp9Q%3D%3D"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 808aa7792fee42b0-EWR
                        alt-svc: h3=":443"; ma=86400
                        2023-09-18 15:34:38 UTC4INData Raw: 65 64 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 73 68 6f 72 74 75 72 6c 2e 61 74 2f 73 4a 4d 51 58 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0d 0a
                        Data Ascii: ed<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>301 Moved Permanently</title></head><body><h1>Moved Permanently</h1><p>The document has moved <a href="https://www.shorturl.at/sJMQX">here</a>.</p></body></html>
                        2023-09-18 15:34:38 UTC4INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        1192.168.2.349708142.250.80.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampkBytes transferredDirectionData
                        2023-09-18 15:34:38 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                        Host: clients2.google.com
                        Connection: keep-alive
                        X-Goog-Update-Interactivity: fg
                        X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                        X-Goog-Update-Updater: chromecrx-104.0.5112.102
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: empty
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2023-09-18 15:34:38 UTC2INHTTP/1.1 200 OK
                        Content-Security-Policy: script-src 'report-sample' 'nonce-zThL2wcexb0AYh8io1wSgw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                        Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                        Pragma: no-cache
                        Expires: Mon, 01 Jan 1990 00:00:00 GMT
                        Date: Mon, 18 Sep 2023 15:34:38 GMT
                        Content-Type: text/xml; charset=UTF-8
                        X-Daynum: 6104
                        X-Daystart: 30878
                        X-Content-Type-Options: nosniff
                        X-Frame-Options: SAMEORIGIN
                        X-XSS-Protection: 1; mode=block
                        Server: GSE
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Connection: close
                        Transfer-Encoding: chunked
                        2023-09-18 15:34:38 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 31 30 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 30 38 37 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                        Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6104" elapsed_seconds="30878"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                        2023-09-18 15:34:38 UTC3INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                        Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                        2023-09-18 15:34:38 UTC3INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        2192.168.2.349711142.250.80.109443C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampkBytes transferredDirectionData
                        2023-09-18 15:34:38 UTC1OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                        Host: accounts.google.com
                        Connection: keep-alive
                        Content-Length: 1
                        Origin: https://www.google.com
                        Content-Type: application/x-www-form-urlencoded
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: empty
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
                        2023-09-18 15:34:38 UTC2OUTData Raw: 20
                        Data Ascii:
                        2023-09-18 15:34:38 UTC4INHTTP/1.1 200 OK
                        Content-Type: application/json; charset=utf-8
                        Access-Control-Allow-Origin: https://www.google.com
                        Access-Control-Allow-Credentials: true
                        X-Content-Type-Options: nosniff
                        Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                        Pragma: no-cache
                        Expires: Mon, 01 Jan 1990 00:00:00 GMT
                        Date: Mon, 18 Sep 2023 15:34:38 GMT
                        Strict-Transport-Security: max-age=31536000; includeSubDomains
                        Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                        Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                        Content-Security-Policy: script-src 'report-sample' 'nonce-38_hBiAggJn5OP6nS1WYGA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                        Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                        Cross-Origin-Opener-Policy: same-origin
                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                        Server: ESF
                        X-XSS-Protection: 0
                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                        Accept-Ranges: none
                        Vary: Accept-Encoding
                        Connection: close
                        Transfer-Encoding: chunked
                        2023-09-18 15:34:38 UTC6INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                        Data Ascii: 11["gaia.l.a.r",[]]
                        2023-09-18 15:34:38 UTC6INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        3192.168.2.349712172.67.143.86443C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampkBytes transferredDirectionData
                        2023-09-18 15:34:38 UTC6OUTGET /sJMQX HTTP/1.1
                        Host: www.shorturl.at
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2023-09-18 15:34:38 UTC6INHTTP/1.1 302 Found
                        Date: Mon, 18 Sep 2023 15:34:38 GMT
                        Content-Type: text/html; charset=UTF-8
                        Transfer-Encoding: chunked
                        Connection: close
                        location: https://veri.luna5sun.ru.com/Cookie=6peH1ygQf92gcoggr4DmfCfHnrsgoYoglVaX3WVLKDt7l3mUbeefbwt0
                        x-frame-options: SAMEORIGIN
                        x-xss-protection: 1; mode=block
                        x-content-type-options: nosniff
                        x-nginx-upstream-cache-status: MISS
                        x-server-powered-by: Engintron
                        CF-Cache-Status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=g0Mqk4Cp4tAHOBea0O8nNnRNp5i%2FFCe9YtyTeop%2FpoOraOSMGEP2njG%2BQ9LWJRZrcQ9lp5Uy8Q1Sk5jIYIlSm7Kycz%2BTiLODy%2Ferq5n8cJB%2F5I6yoTHHojOsbB8h%2Ba%2FfQIY%3D"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 808aa77ccfe74225-EWR
                        alt-svc: h3=":443"; ma=86400
                        2023-09-18 15:34:38 UTC7INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        050100s020406080100

                        Click to jump to process

                        050100s0.0020406080100MB

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:17:34:34
                        Start date:18/09/2023
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://shorturl.at/sJMQX
                        Imagebase:0x7ff61b720000
                        File size:2'852'640 bytes
                        MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:1
                        Start time:17:34:35
                        Start date:18/09/2023
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1760,i,17764110904755911021,4306917296346461542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                        Imagebase:0x7ff61b720000
                        File size:2'852'640 bytes
                        MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        No disassembly