Edit tour

Windows Analysis Report
https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt

Overview

General Information

Sample URL:https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilm
Analysis ID:1369206
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Creates files inside the system directory
URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 3300 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5672 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2248,i,17026360139733351072,7437417933983408100,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6464 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.ptSample URL: PII: ba11@emfa.pt
Source: unknownHTTPS traffic detected: 23.196.40.67:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.196.40.67:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.196.40.67
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.49.152
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.49.152
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.49.152
Source: unknownTCP traffic detected without corresponding DNS query: 23.47.49.152
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm HTTP/1.1Host: ad.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.196.40.67:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.196.40.67:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_3300_1847232531Jump to behavior
Source: classification engineClassification label: clean1.win@16/0@8/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2248,i,17026360139733351072,7437417933983408100,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2248,i,17026360139733351072,7437417933983408100,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1369206 URL: https://ad.doubleclick.net/... Startdate: 03/01/2024 Architecture: WINDOWS Score: 1 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49619 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 ad.doubleclick.net 142.250.114.148, 443, 49734, 49735 GOOGLEUS United States 10->17 19 www.google.com 142.251.116.106, 443, 49738, 49749 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt0%Avira URL Cloudsafe
https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.116.84
truefalse
    high
    ad.doubleclick.net
    142.250.114.148
    truefalse
      high
      www.google.com
      142.251.116.106
      truefalse
        high
        clients.l.google.com
        142.251.116.113
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htmfalse
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    142.250.114.148
                    ad.doubleclick.netUnited States
                    15169GOOGLEUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.251.116.113
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    142.251.116.106
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    142.251.116.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:38.0.0 Ammolite
                    Analysis ID:1369206
                    Start date and time:2024-01-03 11:20:09 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 2m 53s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:CLEAN
                    Classification:clean1.win@16/0@8/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.115.94, 34.104.35.123, 13.85.23.86, 72.21.81.240, 192.229.211.108, 20.242.39.171, 142.251.116.94
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    No created / dropped files found
                    No static file info

                    Download Network PCAP: filteredfull

                    • Total Packets: 98
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 3, 2024 11:20:51.296633005 CET49678443192.168.2.4104.46.162.224
                    Jan 3, 2024 11:20:52.406089067 CET49675443192.168.2.4173.222.162.32
                    Jan 3, 2024 11:20:59.514303923 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.514338017 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.514394045 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.515083075 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.515105009 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.515178919 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.515712023 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.515724897 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.515990973 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.516005039 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.798640966 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.798897028 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.798914909 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.799302101 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.799360037 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.800314903 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.800364971 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.801748037 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.801770926 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.801851034 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.802035093 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.802047014 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.802160978 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:20:59.802174091 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:20:59.803088903 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.803148031 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.804147959 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.804219961 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.804336071 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:20:59.804342985 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:20:59.842158079 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:21:00.012746096 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:21:00.012833118 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.075829983 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:21:00.075891972 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.075898886 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:21:00.075953960 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:21:00.076004028 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.076607943 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.076620102 CET44349731142.251.116.84192.168.2.4
                    Jan 3, 2024 11:21:00.076668024 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.076683044 CET49731443192.168.2.4142.251.116.84
                    Jan 3, 2024 11:21:00.077070951 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:21:00.077286959 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:21:00.077337027 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:21:00.077537060 CET49730443192.168.2.4142.251.116.113
                    Jan 3, 2024 11:21:00.077557087 CET44349730142.251.116.113192.168.2.4
                    Jan 3, 2024 11:21:00.685585976 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.685617924 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:00.685709000 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.690279007 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.690313101 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:00.690392017 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.690664053 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.690676928 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:00.691030025 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:00.691042900 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.003439903 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.003477097 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.003760099 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.003779888 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.003895044 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.003931046 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.004865885 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.004939079 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.005034924 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.005089998 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.006011963 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.006072998 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.006274939 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.006416082 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.006489992 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.048743010 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.055124998 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.055128098 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.055135012 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.055145025 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.099122047 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.100943089 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.283194065 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.283287048 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:01.283404112 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.284271002 CET49734443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:01.284287930 CET44349734142.250.114.148192.168.2.4
                    Jan 3, 2024 11:21:03.751468897 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:03.751502991 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:03.751641035 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:03.752185106 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:03.752192974 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.025302887 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.026608944 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:04.026633024 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.027585983 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.027698994 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:04.038614988 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:04.038686991 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.094599009 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:04.094613075 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:04.140028000 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:04.200419903 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.200445890 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.200696945 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.206605911 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.206617117 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.478981018 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.479048967 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.506973982 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.506992102 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.507282972 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.561903954 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.569808960 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.616734982 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.736124039 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.736320972 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.736341000 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.736366987 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.736377954 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.736377954 CET49739443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.736385107 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.736392021 CET4434973923.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.771934986 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.771971941 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:04.772042990 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.772598028 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:04.772609949 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.041084051 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.041152954 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.045459986 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.045470953 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.045708895 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.050440073 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.096735954 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.322623014 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.322700024 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.322751999 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.325566053 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.325588942 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:05.325627089 CET49740443192.168.2.423.196.40.67
                    Jan 3, 2024 11:21:05.325630903 CET4434974023.196.40.67192.168.2.4
                    Jan 3, 2024 11:21:14.084538937 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:14.084606886 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:14.084661961 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:15.897809029 CET49738443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:21:15.897840023 CET44349738142.251.116.106192.168.2.4
                    Jan 3, 2024 11:21:46.061940908 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:21:46.061964989 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:22:01.758630037 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:22:01.758729935 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:22:01.758902073 CET44349735142.250.114.148192.168.2.4
                    Jan 3, 2024 11:22:01.758990049 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:22:01.758990049 CET49735443192.168.2.4142.250.114.148
                    Jan 3, 2024 11:22:03.667936087 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:03.667990923 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.668087006 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:03.668504000 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:03.668519974 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.937959909 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.938553095 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:03.938574076 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.938879967 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.939696074 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:03.939754963 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:03.983858109 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:10.249712944 CET4972380192.168.2.423.47.49.152
                    Jan 3, 2024 11:22:10.249912977 CET4972480192.168.2.423.47.49.152
                    Jan 3, 2024 11:22:10.381181002 CET804972423.47.49.152192.168.2.4
                    Jan 3, 2024 11:22:10.381247997 CET4972480192.168.2.423.47.49.152
                    Jan 3, 2024 11:22:10.382482052 CET804972323.47.49.152192.168.2.4
                    Jan 3, 2024 11:22:10.382535934 CET4972380192.168.2.423.47.49.152
                    Jan 3, 2024 11:22:13.941879034 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:13.941937923 CET44349749142.251.116.106192.168.2.4
                    Jan 3, 2024 11:22:13.942004919 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:15.720611095 CET49749443192.168.2.4142.251.116.106
                    Jan 3, 2024 11:22:15.720645905 CET44349749142.251.116.106192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 3, 2024 11:20:59.373450994 CET53556841.1.1.1192.168.2.4
                    Jan 3, 2024 11:20:59.380043983 CET5573953192.168.2.41.1.1.1
                    Jan 3, 2024 11:20:59.380783081 CET6291653192.168.2.41.1.1.1
                    Jan 3, 2024 11:20:59.381560087 CET5288853192.168.2.41.1.1.1
                    Jan 3, 2024 11:20:59.382009983 CET5417353192.168.2.41.1.1.1
                    Jan 3, 2024 11:20:59.511810064 CET53557391.1.1.1192.168.2.4
                    Jan 3, 2024 11:20:59.513278961 CET53629161.1.1.1192.168.2.4
                    Jan 3, 2024 11:20:59.513320923 CET53528881.1.1.1192.168.2.4
                    Jan 3, 2024 11:20:59.514265060 CET53541731.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:00.255577087 CET53499981.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:00.552604914 CET5996053192.168.2.41.1.1.1
                    Jan 3, 2024 11:21:00.552855015 CET5141653192.168.2.41.1.1.1
                    Jan 3, 2024 11:21:00.684757948 CET53599601.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:00.685010910 CET53514161.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:03.617625952 CET6335453192.168.2.41.1.1.1
                    Jan 3, 2024 11:21:03.617908955 CET5115153192.168.2.41.1.1.1
                    Jan 3, 2024 11:21:03.749597073 CET53633541.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:03.749927998 CET53511511.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:17.337538004 CET53496191.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:21.820573092 CET138138192.168.2.4192.168.2.255
                    Jan 3, 2024 11:21:36.541697979 CET53578501.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:59.088196993 CET53628371.1.1.1192.168.2.4
                    Jan 3, 2024 11:21:59.210361958 CET53507201.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Jan 3, 2024 11:20:59.380043983 CET192.168.2.41.1.1.10xd7f4Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.380783081 CET192.168.2.41.1.1.10xb66dStandard query (0)clients2.google.com65IN (0x0001)false
                    Jan 3, 2024 11:20:59.381560087 CET192.168.2.41.1.1.10xa1bfStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.382009983 CET192.168.2.41.1.1.10xa973Standard query (0)accounts.google.com65IN (0x0001)false
                    Jan 3, 2024 11:21:00.552604914 CET192.168.2.41.1.1.10xabe0Standard query (0)ad.doubleclick.netA (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:00.552855015 CET192.168.2.41.1.1.10x2bf5Standard query (0)ad.doubleclick.net65IN (0x0001)false
                    Jan 3, 2024 11:21:03.617625952 CET192.168.2.41.1.1.10x83b2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.617908955 CET192.168.2.41.1.1.10xa63dStandard query (0)www.google.com65IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.113A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.101A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.102A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.139A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.138A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.511810064 CET1.1.1.1192.168.2.40xd7f4No error (0)clients.l.google.com142.251.116.100A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:20:59.513278961 CET1.1.1.1192.168.2.40xb66dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:20:59.513320923 CET1.1.1.1192.168.2.40xa1bfNo error (0)accounts.google.com142.251.116.84A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:00.684757948 CET1.1.1.1192.168.2.40xabe0No error (0)ad.doubleclick.net142.250.114.148A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:00.684757948 CET1.1.1.1192.168.2.40xabe0No error (0)ad.doubleclick.net142.250.114.149A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:00.685010910 CET1.1.1.1192.168.2.40x2bf5No error (0)ad.doubleclick.net65IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.106A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.147A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.105A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.104A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.103A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749597073 CET1.1.1.1192.168.2.40x83b2No error (0)www.google.com142.251.116.99A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:03.749927998 CET1.1.1.1192.168.2.40xa63dNo error (0)www.google.com65IN (0x0001)false
                    Jan 3, 2024 11:21:16.356622934 CET1.1.1.1192.168.2.40xa2edNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:21:16.356622934 CET1.1.1.1192.168.2.40xa2edNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:29.304810047 CET1.1.1.1192.168.2.40x28bcNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:21:29.304810047 CET1.1.1.1192.168.2.40x28bcNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:21:51.663578987 CET1.1.1.1192.168.2.40xd747No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:21:51.663578987 CET1.1.1.1192.168.2.40xd747No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    Jan 3, 2024 11:22:12.024174929 CET1.1.1.1192.168.2.40x9ae7No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Jan 3, 2024 11:22:12.024174929 CET1.1.1.1192.168.2.40x9ae7No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • clients2.google.com
                    • accounts.google.com
                    • ad.doubleclick.net
                    • fs.microsoft.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449730142.251.116.1134435672C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-01-03 10:20:59 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-117.0.5938.132
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-01-03 10:21:00 UTC731INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-g-apaDnKb5nMXMK0UiS0Aw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Wed, 03 Jan 2024 10:21:00 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6211
                    X-Daystart: 8460
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-01-03 10:21:00 UTC521INData Raw: 32 63 38 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 31 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 38 34 36 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22 20
                    Data Ascii: 2c8<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6211" elapsed_seconds="8460"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2024-01-03 10:21:00 UTC198INData Raw: 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 3f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2024-01-03 10:21:00 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449731142.251.116.844435672C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-01-03 10:20:59 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                    2024-01-03 10:20:59 UTC1OUTData Raw: 20
                    Data Ascii:
                    2024-01-03 10:21:00 UTC1627INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Wed, 03 Jan 2024 10:21:00 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Content-Security-Policy: script-src 'report-sample' 'nonce-7n7Oe4XO3vqrvRcZcM9piw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Cross-Origin-Opener-Policy: same-origin
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-01-03 10:21:00 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2024-01-03 10:21:00 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    2192.168.2.449734142.250.114.1484435672C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-01-03 10:21:01 UTC992OUTGET /ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm HTTP/1.1
                    Host: ad.doubleclick.net
                    Connection: keep-alive
                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                    sec-ch-ua-mobile: ?0
                    sec-ch-ua-platform: "Windows"
                    Upgrade-Insecure-Requests: 1
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                    X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: navigate
                    Sec-Fetch-User: ?1
                    Sec-Fetch-Dest: document
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-01-03 10:21:01 UTC970INHTTP/1.1 204 No Content
                    P3P: policyref="https://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
                    Timing-Allow-Origin: *
                    Cross-Origin-Resource-Policy: cross-origin
                    Date: Wed, 03 Jan 2024 10:21:01 GMT
                    Pragma: no-cache
                    Expires: Fri, 01 Jan 1990 00:00:00 GMT
                    Cache-Control: no-cache, must-revalidate
                    Content-Type: text/html; charset=UTF-8
                    X-Content-Type-Options: nosniff
                    Server: cafe
                    Content-Length: 0
                    X-XSS-Protection: 0
                    Set-Cookie: APC=AfxxVi5ZR-Rv7ehc-ledtfPerQsbgmJL9I7T4IEuiOuLthTlHYcLwg; expires=Mon, 01-Jul-2024 10:21:01 GMT; path=/; domain=doubleclick.net; Secure; SameSite=none; Partitioned
                    Set-Cookie: IDE=AHWqTUm6x2wvDZStYLkBP17JLyaaYdtIUaw89QQgNmvJrQAkWDMMiL7EOAMM35Mu57c; expires=Fri, 02-Jan-2026 10:21:01 GMT; path=/; domain=.doubleclick.net; Secure; HttpOnly; SameSite=none
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Connection: close


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    3192.168.2.44973923.196.40.67443
                    TimestampBytes transferredDirectionData
                    2024-01-03 10:21:04 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-01-03 10:21:04 UTC495INHTTP/1.1 200 OK
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    Content-Type: application/octet-stream
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    Server: ECAcc (chd/0758)
                    X-CID: 11
                    X-Ms-ApiVersion: Distribute 1.2
                    X-Ms-Region: prod-eus2-z1
                    Cache-Control: public, max-age=50024
                    Date: Wed, 03 Jan 2024 10:21:04 GMT
                    Connection: close
                    X-CID: 2


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    4192.168.2.44974023.196.40.67443
                    TimestampBytes transferredDirectionData
                    2024-01-03 10:21:05 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                    Connection: Keep-Alive
                    Accept: */*
                    Accept-Encoding: identity
                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                    Range: bytes=0-2147483646
                    User-Agent: Microsoft BITS/7.8
                    Host: fs.microsoft.com
                    2024-01-03 10:21:05 UTC530INHTTP/1.1 200 OK
                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                    Content-Type: application/octet-stream
                    ApiVersion: Distribute 1.1
                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                    X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
                    Cache-Control: public, max-age=50053
                    Date: Wed, 03 Jan 2024 10:21:05 GMT
                    Content-Length: 55
                    Connection: close
                    X-CID: 2
                    2024-01-03 10:21:05 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                    020406080s020406080100

                    Click to jump to process

                    020406080s0.0050100MB

                    Click to jump to process

                    Target ID:0
                    Start time:11:20:54
                    Start date:03/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:11:20:57
                    Start date:03/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2248,i,17026360139733351072,7437417933983408100,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:11:20:59
                    Start date:03/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ad.doubleclick.net/ddm/trackclk/N388808.2679425NORWEGIAN/B11346953.151051694;dc_trk_aid=321626246;dc_trk_cid=73644999;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=?https://nslk.harikafilmizle.org/h0-0p-0i.htm#ba11@emfa.pt
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly