Edit tour

Windows Analysis Report
https://rdap.arin.net/registry/ip/104.193.88.0

Overview

General Information

Sample URL:https://rdap.arin.net/registry/ip/104.193.88.0
Analysis ID:1387159
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files inside the system directory
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1440 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2224,i,8779192040810359767,11844691577958903530,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4448 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rdap.arin.net/registry/ip/104.193.88.0 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://rdap.arin.net/registry/ip/104.193.88.0HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49722 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /registry/ip/104.193.88.0 HTTP/1.1Host: rdap.arin.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: rdap.arin.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://rdap.arin.net/registry/ip/104.193.88.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 05 Feb 2024 22:00:55 GMTServer: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fipsContent-Length: 209Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: chromecache_57.2.drString found in binary or memory: https://rdap.arin.net/registry/entity/BUL-5
Source: chromecache_57.2.drString found in binary or memory: https://rdap.arin.net/registry/entity/GINOC1-ARIN
Source: chromecache_57.2.drString found in binary or memory: https://rdap.arin.net/registry/entity/GINOC2-ARIN
Source: chromecache_57.2.drString found in binary or memory: https://rdap.arin.net/registry/ip/104.193.88.0
Source: chromecache_57.2.drString found in binary or memory: https://whois.arin.net/rest/net/NET-104-193-88-0-1
Source: chromecache_57.2.drString found in binary or memory: https://whois.arin.net/rest/org/BUL-5
Source: chromecache_57.2.drString found in binary or memory: https://whois.arin.net/rest/poc/GINOC1-ARIN
Source: chromecache_57.2.drString found in binary or memory: https://whois.arin.net/rest/poc/GINOC2-ARIN
Source: chromecache_57.2.drString found in binary or memory: https://www.arin.net/resources/registry/whois/inaccuracy_reporting/
Source: chromecache_57.2.drString found in binary or memory: https://www.arin.net/resources/registry/whois/tou/
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.5:49716 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1440_1296849057Jump to behavior
Source: classification engineClassification label: clean1.win@16/10@10/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2224,i,8779192040810359767,11844691577958903530,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rdap.arin.net/registry/ip/104.193.88.0
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2224,i,8779192040810359767,11844691577958903530,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1387159 URL: https://rdap.arin.net/regis... Startdate: 05/02/2024 Architecture: WINDOWS Score: 1 14 clients1.google.com 2->14 16 clients.l.google.com 2->16 6 chrome.exe 9 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 18 192.168.2.22 unknown unknown 6->18 20 192.168.2.4 unknown unknown 6->20 22 2 other IPs or domains 6->22 11 chrome.exe 6->11         started        process5 dnsIp6 24 clients.l.google.com 142.250.9.101, 443, 49706 GOOGLEUS United States 11->24 26 www.google.com 172.217.215.104, 443, 49714, 49727 GOOGLEUS United States 11->26 28 3 other IPs or domains 11->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://rdap.arin.net/registry/ip/104.193.88.00%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
74.125.136.84
truefalse
    high
    www.google.com
    172.217.215.104
    truefalse
      high
      clients.l.google.com
      142.250.9.101
      truefalse
        high
        rdap.arin.net
        199.71.0.160
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            windowsupdatebg.s.llnwi.net
            69.164.42.0
            truefalse
              unknown
              clients1.google.com
              unknown
              unknownfalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://rdap.arin.net/registry/ip/104.193.88.0false
                    high
                    https://rdap.arin.net/favicon.icofalse
                      high
                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                        high
                        https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                          high
                          NameSourceMaliciousAntivirus DetectionReputation
                          https://whois.arin.net/rest/poc/GINOC2-ARINchromecache_57.2.drfalse
                            high
                            https://rdap.arin.net/registry/entity/GINOC1-ARINchromecache_57.2.drfalse
                              high
                              https://whois.arin.net/rest/net/NET-104-193-88-0-1chromecache_57.2.drfalse
                                high
                                https://whois.arin.net/rest/poc/GINOC1-ARINchromecache_57.2.drfalse
                                  high
                                  https://rdap.arin.net/registry/entity/BUL-5chromecache_57.2.drfalse
                                    high
                                    https://rdap.arin.net/registry/entity/GINOC2-ARINchromecache_57.2.drfalse
                                      high
                                      https://www.arin.net/resources/registry/whois/inaccuracy_reporting/chromecache_57.2.drfalse
                                        high
                                        https://www.arin.net/resources/registry/whois/tou/chromecache_57.2.drfalse
                                          high
                                          https://whois.arin.net/rest/org/BUL-5chromecache_57.2.drfalse
                                            high
                                            • No. of IPs < 25%
                                            • 25% < No. of IPs < 50%
                                            • 50% < No. of IPs < 75%
                                            • 75% < No. of IPs
                                            IPDomainCountryFlagASNASN NameMalicious
                                            74.125.136.84
                                            accounts.google.comUnited States
                                            15169GOOGLEUSfalse
                                            239.255.255.250
                                            unknownReserved
                                            unknownunknownfalse
                                            172.217.215.104
                                            www.google.comUnited States
                                            15169GOOGLEUSfalse
                                            142.250.9.101
                                            clients.l.google.comUnited States
                                            15169GOOGLEUSfalse
                                            199.71.0.160
                                            rdap.arin.netUnited States
                                            393220ARIN-PFS-SJCUSfalse
                                            IP
                                            192.168.2.22
                                            192.168.2.4
                                            192.168.2.5
                                            Joe Sandbox version:39.0.0 Ruby
                                            Analysis ID:1387159
                                            Start date and time:2024-02-05 22:59:56 +01:00
                                            Joe Sandbox product:CloudBasic
                                            Overall analysis duration:0h 3m 17s
                                            Hypervisor based Inspection enabled:false
                                            Report type:full
                                            Cookbook file name:browseurl.jbs
                                            Sample URL:https://rdap.arin.net/registry/ip/104.193.88.0
                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                            Number of analysed new started processes analysed:7
                                            Number of new started drivers analysed:0
                                            Number of existing processes analysed:0
                                            Number of existing drivers analysed:0
                                            Number of injected processes analysed:0
                                            Technologies:
                                            • HCA enabled
                                            • EGA enabled
                                            • AMSI enabled
                                            Analysis Mode:default
                                            Analysis stop reason:Timeout
                                            Detection:CLEAN
                                            Classification:clean1.win@16/10@10/8
                                            EGA Information:Failed
                                            HCA Information:
                                            • Successful, ratio: 100%
                                            • Number of executed functions: 0
                                            • Number of non-executed functions: 0
                                            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                                            • Excluded IPs from analysis (whitelisted): 142.250.105.94, 34.104.35.123, 20.114.59.183, 192.229.211.108, 23.40.205.11, 23.40.205.49, 23.40.205.35, 23.40.205.18, 23.40.205.73, 23.40.205.26, 23.40.205.81, 23.40.205.56, 23.40.205.34, 20.3.187.198, 72.21.81.240, 64.233.176.94, 69.164.42.0
                                            • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                                            • Not all processes where analyzed, report is missing behavior information
                                            • Report size getting too big, too many NtOpenFile calls found.
                                            • Report size getting too big, too many NtSetInformationFile calls found.
                                            • VT rate limit hit for: https://rdap.arin.net/registry/ip/104.193.88.0
                                            No simulations
                                            No context
                                            No context
                                            No context
                                            No context
                                            No context
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 5 21:00:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2677
                                            Entropy (8bit):3.978621720308257
                                            Encrypted:false
                                            SSDEEP:48:8CdjTLLjHBidAKZdA19ehwiZUklqehSy+3:8a7nFy
                                            MD5:55F8D65FEF1D9823C72D089C346F4531
                                            SHA1:888EA592AC55BC2F9973241291A78BC066D6AB6D
                                            SHA-256:53A6AB933C916801732362E40B5F019A0D0EFA995760A4FCA5D60C0D6904C14F
                                            SHA-512:E1717CEDC52DADCF02C50B573DE11312E47F8CB80EE4A07862243D322EC37B5A30DA048C9513A5594614634F564DDD1AA5EBC10277C5BBB5168772CCF8B8A34C
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,.....@..~X..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 5 21:00:53 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2679
                                            Entropy (8bit):3.9952038013301756
                                            Encrypted:false
                                            SSDEEP:48:8qdjTLLjHBidAKZdA1weh/iZUkAQkqeh1y+2:8S7N9QQy
                                            MD5:BCFF6DE34613BCF392932104CED8E065
                                            SHA1:A3BA80E4A166375302888B65669A9C2DD18F9597
                                            SHA-256:A06E205CC1576BC9D93BCC0FE226E0CEA304462978FC227F69677FCB985FCC73
                                            SHA-512:8B3ADD48CD4440CA6C1290751081054ED2379DD6308384B8EE0011FDE3718C5F47A7566FFC98DB4FA0A03D8B0F071A1BBEBE8D858B35943F2E15A30A510707A2
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,........~X..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2693
                                            Entropy (8bit):4.005519080323737
                                            Encrypted:false
                                            SSDEEP:48:8xkdjTLLsHBidAKZdA14tseh7sFiZUkmgqeh7sry+BX:8xM7Qnxy
                                            MD5:F971FFBC19A0497977F15FCFB62C510A
                                            SHA1:26ED67ED0410E60990CD9FA6BAD167D5D2FD6F9E
                                            SHA-256:B1B6DF91F91AA95DCC824274C83B8A33C954D81598848718847EFE72DEEEBD42
                                            SHA-512:9511EED83924947FD603AAACA23B36E8088514C1C952F1D97D211AE74FFD21C3558F825F8FE6229FC9D93DE01355E1CD6542DD61FB071B0549944EE675ABAA29
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 5 21:00:53 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2681
                                            Entropy (8bit):3.9923422306395264
                                            Encrypted:false
                                            SSDEEP:48:8mdjTLLjHBidAKZdA1vehDiZUkwqehJy+R:827ujy
                                            MD5:4348682793C2233802980B98FC0C41B8
                                            SHA1:D5B7242967A0C6A4901B0783CE4ED4EB59C515FF
                                            SHA-256:FA79DBBF21B6AF973A6D26299AD71FD26802199AB90BE502894AFE1A7C7A563A
                                            SHA-512:2A197316C49B660C303A5127B5B4339D7D2C438CCF67E13B89E27BD6D1E5633F30250A9C54ECB3BFA0E00DCF9ABBBBD3FECF01C610487FECFC03110AE7C81E6C
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,........~X..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 5 21:00:53 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2681
                                            Entropy (8bit):3.9816650401268667
                                            Encrypted:false
                                            SSDEEP:48:8YdjTLLjHBidAKZdA1hehBiZUk1W1qehHy+C:8I7e9ny
                                            MD5:88578E9E97A3D8246C41CF1E45E0CF09
                                            SHA1:943921AA2246C4570C682CA7B7BB97781E036989
                                            SHA-256:F83C8A070A66E4A322F1AC5B0AB37CEF189468300244E824838D34CE481268D8
                                            SHA-512:C232F69E6B011D0B97D6B7E0AA464E06B8D4E086496F400F96A644AA2CDFF576178C4D434F26A20B8111FC112615677CA535D5B108EFBA58A13D7B55739F48BD
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,....#,..~X..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 5 21:00:53 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                            Category:dropped
                                            Size (bytes):2683
                                            Entropy (8bit):3.9910554228598483
                                            Encrypted:false
                                            SSDEEP:48:89djTLLjHBidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbxy+yT+:8z7AT/TbxWOvTbxy7T
                                            MD5:C157F263B8316AE214867D6B18493BE2
                                            SHA1:CAD40FBC985851E448FA3C64E307E50896430F52
                                            SHA-256:D4C960A755BF0686FE134EC25C45BB5DBC5AEAE531F606FB1EE1653B904C224F
                                            SHA-512:EACF440D205862D723DF78BC4D38F577EFB4D9410A54F9223C4F8FB6DB80748AF2322B2861DE2D45330E000CF906A71ED8D04B5400FFF6482C786E662A5D6C8A
                                            Malicious:false
                                            Reputation:low
                                            Preview:L..................F.@.. ...$+.,.....|..~X..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IEX......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VEX......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VEX......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VEX............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VEX.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........H@/......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:JSON data
                                            Category:downloaded
                                            Size (bytes):6309
                                            Entropy (8bit):4.775173465973005
                                            Encrypted:false
                                            SSDEEP:192:HPr57/n0r/irYXvvOwXJRWbWYhJuRWVLnrM:vr5T0r/irYfWwZUb9XMk4
                                            MD5:45148B83F0FF24AC36F4A5AD4455EABB
                                            SHA1:BBDB4F0A21AF558AEE437B61873C421C467666D2
                                            SHA-256:18E51F5B22E15FA49ABB49DDA1A46D6EDC74A3DBC1873EC457905C9FCDB6305D
                                            SHA-512:9A3C2616290ED0066B3DC3AC6A075A4CA9EC2ABA1739016C4F25FE6CFDFFCAED8222FA4198ED0D3D4F16A29AA5C19ACD18EEC01E8D2AE677689F56BC65DD13BF
                                            Malicious:false
                                            Reputation:low
                                            URL:https://rdap.arin.net/registry/ip/104.193.88.0
                                            Preview:{. "rdapConformance" : [ "nro_rdap_profile_0", "rdap_level_0", "cidr0", "arin_originas0" ],. "notices" : [ {. "title" : "Terms of Service",. "description" : [ "By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use" ],. "links" : [ {. "value" : "https://rdap.arin.net/registry/ip/104.193.88.0",. "rel" : "terms-of-service",. "type" : "text/html",. "href" : "https://www.arin.net/resources/registry/whois/tou/". } ]. }, {. "title" : "Whois Inaccuracy Reporting",. "description" : [ "If you see inaccuracies in the results, please visit: " ],. "links" : [ {. "value" : "https://rdap.arin.net/registry/ip/104.193.88.0",. "rel" : "inaccuracy-report",. "type" : "text/html",. "href" : "https://www.arin.net/resources/registry/whois/inaccuracy_reporting/". } ]. }, {. "title" : "Copyright Notice",. "description" : [ "Copyright 1997-2024, American Registry for Internet Numbers, Ltd." ]. } ],. "hand
                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            File Type:HTML document, ASCII text
                                            Category:downloaded
                                            Size (bytes):209
                                            Entropy (8bit):5.143049113812332
                                            Encrypted:false
                                            SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3ezJLM4KCezocKqD:J0+oxBeRmR9etdzRxy17ez1T
                                            MD5:18FFB59B61525F781CF9251045BE575D
                                            SHA1:BD7318B00B15B7A1C8A48524419FA2E5C27A5B6D
                                            SHA-256:B6682CAB65D3243B5B75EFB7279DBF49491957484780F2BA0A87632CC0E25642
                                            SHA-512:A032F853ABD9492232E1183D1CB1D14110B623F2E9DEC56B7B64DD576A0317DDA8D51125763E11D6642433C5364B2BD10A994EE4F1514629A4950BBAB3ABA499
                                            Malicious:false
                                            Reputation:low
                                            URL:https://rdap.arin.net/favicon.ico
                                            Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL /favicon.ico was not found on this server.</p>.</body></html>.
                                            No static file info

                                            Download Network PCAP: filteredfull

                                            • Total Packets: 117
                                            • 443 (HTTPS)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Feb 5, 2024 23:00:44.203133106 CET49675443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:44.203263998 CET49674443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:44.312501907 CET49673443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:52.570492029 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.570502043 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.570547104 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.571408033 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.571444035 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.571496010 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.572490931 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.572500944 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.572772026 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.572784901 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.811801910 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.812165976 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.812199116 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.813695908 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.813770056 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.817337036 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.817449093 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.817966938 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:52.817981005 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:52.831286907 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.831490993 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.831500053 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.831875086 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.831943989 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.832586050 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.832645893 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.833672047 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.833734035 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.833832026 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:52.833837032 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:52.873120070 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:53.027756929 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:53.028134108 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:53.028202057 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:53.028940916 CET49707443192.168.2.574.125.136.84
                                            Feb 5, 2024 23:00:53.028964043 CET4434970774.125.136.84192.168.2.5
                                            Feb 5, 2024 23:00:53.037913084 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:53.037956953 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:53.066122055 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:53.066277981 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:53.066335917 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:53.067178011 CET49706443192.168.2.5142.250.9.101
                                            Feb 5, 2024 23:00:53.067198038 CET44349706142.250.9.101192.168.2.5
                                            Feb 5, 2024 23:00:53.809056044 CET49675443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:53.871656895 CET49674443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:53.918508053 CET49673443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:54.737797022 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.737853050 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:54.737926006 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.738857031 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.738903999 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:54.738975048 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.740139008 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.740153074 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:54.740407944 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:54.740433931 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.084306955 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.084803104 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.084866047 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.086148024 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.086220026 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.086268902 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.087474108 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.087507010 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.088665009 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.088777065 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.088871956 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.088891029 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.088960886 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.089015007 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.090009928 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.090104103 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.130032063 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.130034924 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.130059958 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.177122116 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.274774075 CET4434970323.1.237.91192.168.2.5
                                            Feb 5, 2024 23:00:55.274945974 CET49703443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:00:55.403692007 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.403719902 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.403763056 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.403800964 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.403836966 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.403877020 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.560342073 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.560475111 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.560507059 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.560529947 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.560569048 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.571126938 CET49710443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.571146965 CET44349710199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.657883883 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.705904961 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.815926075 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.816040039 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:55.816088915 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.825896978 CET49711443192.168.2.5199.71.0.160
                                            Feb 5, 2024 23:00:55.825918913 CET44349711199.71.0.160192.168.2.5
                                            Feb 5, 2024 23:00:57.140295982 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.140331030 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.140459061 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.144556046 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.144567013 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.360120058 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.368071079 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.368083954 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.369144917 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.369210005 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.374834061 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.374910116 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.418497086 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.418504953 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:00:57.465755939 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:00:57.623750925 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:57.623800993 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:57.623872042 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:57.642627001 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:57.642651081 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:57.856183052 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:57.856266975 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:57.906029940 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:57.906060934 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:57.906445980 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:57.950140953 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.371349096 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.413899899 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.473815918 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.473927021 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.473980904 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.474076986 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.474092007 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.474107027 CET49715443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.474113941 CET4434971523.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.545224905 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.545250893 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.545320988 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.546102047 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.546113014 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.755935907 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.756526947 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.761555910 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.761564016 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.761954069 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:58.771413088 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:58.817892075 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:59.065800905 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:59.065989971 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:59.068382025 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:59.072657108 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:59.072690964 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:00:59.072735071 CET49716443192.168.2.523.63.206.91
                                            Feb 5, 2024 23:00:59.072745085 CET4434971623.63.206.91192.168.2.5
                                            Feb 5, 2024 23:01:05.622488976 CET49703443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:05.622922897 CET49703443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:05.625989914 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:05.626033068 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:05.626138926 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:05.628351927 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:05.628386021 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:05.771359921 CET4434970323.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:05.771785021 CET4434970323.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.004352093 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.004439116 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.088519096 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.088556051 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.088989973 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.089046001 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.089801073 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.089835882 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.090006113 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.090013981 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.336718082 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.336781025 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.337044954 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:06.337094069 CET4434972223.1.237.91192.168.2.5
                                            Feb 5, 2024 23:01:06.337146044 CET49722443192.168.2.523.1.237.91
                                            Feb 5, 2024 23:01:07.359539986 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:07.359611034 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:07.359752893 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:08.795764923 CET49714443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:08.795789957 CET44349714172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.301593065 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.301628113 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.301743984 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.302373886 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.302392960 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.514194965 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.559552908 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.714942932 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.714951038 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.715526104 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.740323067 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:01:57.740458012 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:01:57.786823988 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:02:07.527103901 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:02:07.527184010 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:02:07.527396917 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:02:08.853252888 CET49727443192.168.2.5172.217.215.104
                                            Feb 5, 2024 23:02:08.853287935 CET44349727172.217.215.104192.168.2.5
                                            Feb 5, 2024 23:02:21.805368900 CET49730443192.168.2.564.233.176.138
                                            Feb 5, 2024 23:02:21.805414915 CET4434973064.233.176.138192.168.2.5
                                            Feb 5, 2024 23:02:21.805485010 CET49730443192.168.2.564.233.176.138
                                            Feb 5, 2024 23:02:21.805845976 CET49730443192.168.2.564.233.176.138
                                            Feb 5, 2024 23:02:21.805860996 CET4434973064.233.176.138192.168.2.5
                                            Feb 5, 2024 23:02:22.016267061 CET4434973064.233.176.138192.168.2.5
                                            Feb 5, 2024 23:02:22.059557915 CET49730443192.168.2.564.233.176.138
                                            TimestampSource PortDest PortSource IPDest IP
                                            Feb 5, 2024 23:00:52.389679909 CET6433053192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:52.390072107 CET5358053192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:52.390630007 CET5154053192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:52.392591953 CET6004353192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:52.507205963 CET53643301.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:52.507356882 CET53535801.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:52.508138895 CET53515401.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:52.509696007 CET53600431.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:52.553636074 CET53590611.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:53.242913008 CET53550391.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:54.549345970 CET5871053192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:54.552025080 CET4966153192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:54.669578075 CET53587101.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:54.740474939 CET53496611.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:57.018596888 CET5920653192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:57.019720078 CET5325753192.168.2.51.1.1.1
                                            Feb 5, 2024 23:00:57.135848045 CET53592061.1.1.1192.168.2.5
                                            Feb 5, 2024 23:00:57.137013912 CET53532571.1.1.1192.168.2.5
                                            Feb 5, 2024 23:01:10.336647034 CET53573261.1.1.1192.168.2.5
                                            Feb 5, 2024 23:01:29.735019922 CET53504351.1.1.1192.168.2.5
                                            Feb 5, 2024 23:01:52.498581886 CET53636701.1.1.1192.168.2.5
                                            Feb 5, 2024 23:01:52.512867928 CET53648131.1.1.1192.168.2.5
                                            Feb 5, 2024 23:02:20.896758080 CET53591701.1.1.1192.168.2.5
                                            Feb 5, 2024 23:02:21.686548948 CET5470153192.168.2.51.1.1.1
                                            Feb 5, 2024 23:02:21.686654091 CET5340753192.168.2.51.1.1.1
                                            Feb 5, 2024 23:02:21.803836107 CET53547011.1.1.1192.168.2.5
                                            Feb 5, 2024 23:02:21.804809093 CET53534071.1.1.1192.168.2.5
                                            TimestampSource IPDest IPChecksumCodeType
                                            Feb 5, 2024 23:00:54.740545988 CET192.168.2.51.1.1.1c211(Port unreachable)Destination Unreachable
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Feb 5, 2024 23:00:52.389679909 CET192.168.2.51.1.1.10x4b7aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.390072107 CET192.168.2.51.1.1.10x7083Standard query (0)accounts.google.com65IN (0x0001)false
                                            Feb 5, 2024 23:00:52.390630007 CET192.168.2.51.1.1.10xa6b4Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.392591953 CET192.168.2.51.1.1.10x1e79Standard query (0)clients2.google.com65IN (0x0001)false
                                            Feb 5, 2024 23:00:54.549345970 CET192.168.2.51.1.1.10x6ccaStandard query (0)rdap.arin.netA (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:54.552025080 CET192.168.2.51.1.1.10x5b7cStandard query (0)rdap.arin.net65IN (0x0001)false
                                            Feb 5, 2024 23:00:57.018596888 CET192.168.2.51.1.1.10xe1b4Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.019720078 CET192.168.2.51.1.1.10x253eStandard query (0)www.google.com65IN (0x0001)false
                                            Feb 5, 2024 23:02:21.686548948 CET192.168.2.51.1.1.10x9929Standard query (0)clients1.google.comA (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.686654091 CET192.168.2.51.1.1.10xe21cStandard query (0)clients1.google.com65IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Feb 5, 2024 23:00:52.507205963 CET1.1.1.1192.168.2.50x4b7aNo error (0)accounts.google.com74.125.136.84A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.101A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.100A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.139A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.113A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.102A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.508138895 CET1.1.1.1192.168.2.50xa6b4No error (0)clients.l.google.com142.250.9.138A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:52.509696007 CET1.1.1.1192.168.2.50x1e79No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                            Feb 5, 2024 23:00:54.669578075 CET1.1.1.1192.168.2.50x6ccaNo error (0)rdap.arin.net199.71.0.160A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:54.669578075 CET1.1.1.1192.168.2.50x6ccaNo error (0)rdap.arin.net199.212.0.160A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:54.669578075 CET1.1.1.1192.168.2.50x6ccaNo error (0)rdap.arin.net199.5.26.160A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.104A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.147A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.103A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.106A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.99A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.135848045 CET1.1.1.1192.168.2.50xe1b4No error (0)www.google.com172.217.215.105A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:00:57.137013912 CET1.1.1.1192.168.2.50x253eNo error (0)www.google.com65IN (0x0001)false
                                            Feb 5, 2024 23:01:05.053595066 CET1.1.1.1192.168.2.50xbf70No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                            Feb 5, 2024 23:01:05.053595066 CET1.1.1.1192.168.2.50xbf70No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:06.437328100 CET1.1.1.1192.168.2.50x9494No error (0)windowsupdatebg.s.llnwi.net69.164.42.0A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients1.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.138A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.102A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.113A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.100A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.101A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.803836107 CET1.1.1.1192.168.2.50x9929No error (0)clients.l.google.com64.233.176.139A (IP address)IN (0x0001)false
                                            Feb 5, 2024 23:02:21.804809093 CET1.1.1.1192.168.2.50xe21cNo error (0)clients1.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                            • accounts.google.com
                                            • clients2.google.com
                                            • rdap.arin.net
                                            • https:
                                              • www.bing.com
                                            • fs.microsoft.com
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.54970774.125.136.844433472C:\Program Files\Google\Chrome\Application\chrome.exe
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:52 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                            Host: accounts.google.com
                                            Connection: keep-alive
                                            Content-Length: 1
                                            Origin: https://www.google.com
                                            Content-Type: application/x-www-form-urlencoded
                                            Sec-Fetch-Site: none
                                            Sec-Fetch-Mode: no-cors
                                            Sec-Fetch-Dest: empty
                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                            Accept-Encoding: gzip, deflate, br
                                            Accept-Language: en-US,en;q=0.9
                                            Cookie: NID=511=Ef5vPFGw-MZYo5hwe-0ThAVslbxbmvdVZwcHnqVzWHAU14v53MN1VvwvQq8baYfg2-IAtqZBV5NOL5rvj2NWIqrz377UhLdHtOgE-tJaBlUBYJEhuGsQdqni3oTJg0brqv1djdiLJyvTSUhdK-c5JWadCSsULPLzhSx-F-6wOg4
                                            2024-02-05 22:00:52 UTC1OUTData Raw: 20
                                            Data Ascii:
                                            2024-02-05 22:00:53 UTC1799INHTTP/1.1 200 OK
                                            Content-Type: application/json; charset=utf-8
                                            Access-Control-Allow-Origin: https://www.google.com
                                            Access-Control-Allow-Credentials: true
                                            X-Content-Type-Options: nosniff
                                            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                            Pragma: no-cache
                                            Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                            Date: Mon, 05 Feb 2024 22:00:52 GMT
                                            Strict-Transport-Security: max-age=31536000; includeSubDomains
                                            Content-Security-Policy: script-src 'report-sample' 'nonce-amxQEUfUMldpBLyOI2a6wQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                            Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                            Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                            Cross-Origin-Opener-Policy: same-origin
                                            Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                            Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                                            reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQBiIR6OKVtb17EJLLj-_QozALO_F6Q"
                                            Server: ESF
                                            X-XSS-Protection: 0
                                            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                            Accept-Ranges: none
                                            Vary: Accept-Encoding
                                            Connection: close
                                            Transfer-Encoding: chunked
                                            2024-02-05 22:00:53 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                            Data Ascii: 11["gaia.l.a.r",[]]
                                            2024-02-05 22:00:53 UTC5INData Raw: 30 0d 0a 0d 0a
                                            Data Ascii: 0


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            1192.168.2.549706142.250.9.1014433472C:\Program Files\Google\Chrome\Application\chrome.exe
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:52 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                            Host: clients2.google.com
                                            Connection: keep-alive
                                            X-Goog-Update-Interactivity: fg
                                            X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                            X-Goog-Update-Updater: chromecrx-117.0.5938.132
                                            Sec-Fetch-Site: none
                                            Sec-Fetch-Mode: no-cors
                                            Sec-Fetch-Dest: empty
                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                            Accept-Encoding: gzip, deflate, br
                                            Accept-Language: en-US,en;q=0.9
                                            2024-02-05 22:00:53 UTC732INHTTP/1.1 200 OK
                                            Content-Security-Policy: script-src 'report-sample' 'nonce-Zm4POvoUgjLRvKFG7rXiIg' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                            Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                            Pragma: no-cache
                                            Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                            Date: Mon, 05 Feb 2024 22:00:53 GMT
                                            Content-Type: text/xml; charset=UTF-8
                                            X-Daynum: 6244
                                            X-Daystart: 50453
                                            X-Content-Type-Options: nosniff
                                            X-Frame-Options: SAMEORIGIN
                                            X-XSS-Protection: 1; mode=block
                                            Server: GSE
                                            Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                            Accept-Ranges: none
                                            Vary: Accept-Encoding
                                            Connection: close
                                            Transfer-Encoding: chunked
                                            2024-02-05 22:00:53 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 34 34 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 35 30 34 35 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                            Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6244" elapsed_seconds="50453"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                            2024-02-05 22:00:53 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                            Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                            2024-02-05 22:00:53 UTC5INData Raw: 30 0d 0a 0d 0a
                                            Data Ascii: 0


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            2192.168.2.549710199.71.0.1604433472C:\Program Files\Google\Chrome\Application\chrome.exe
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:55 UTC680OUTGET /registry/ip/104.193.88.0 HTTP/1.1
                                            Host: rdap.arin.net
                                            Connection: keep-alive
                                            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                            sec-ch-ua-mobile: ?0
                                            sec-ch-ua-platform: "Windows"
                                            Upgrade-Insecure-Requests: 1
                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                            Sec-Fetch-Site: none
                                            Sec-Fetch-Mode: navigate
                                            Sec-Fetch-User: ?1
                                            Sec-Fetch-Dest: document
                                            Accept-Encoding: gzip, deflate, br
                                            Accept-Language: en-US,en;q=0.9
                                            2024-02-05 22:00:55 UTC215INHTTP/1.1 200
                                            Date: Mon, 05 Feb 2024 22:00:54 GMT
                                            Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips
                                            Content-Type: application/rdap+json
                                            Content-Length: 6309
                                            Access-Control-Allow-Origin: *
                                            Connection: close
                                            2024-02-05 22:00:55 UTC2333INData Raw: 7b 0a 20 20 22 72 64 61 70 43 6f 6e 66 6f 72 6d 61 6e 63 65 22 20 3a 20 5b 20 22 6e 72 6f 5f 72 64 61 70 5f 70 72 6f 66 69 6c 65 5f 30 22 2c 20 22 72 64 61 70 5f 6c 65 76 65 6c 5f 30 22 2c 20 22 63 69 64 72 30 22 2c 20 22 61 72 69 6e 5f 6f 72 69 67 69 6e 61 73 30 22 20 5d 2c 0a 20 20 22 6e 6f 74 69 63 65 73 22 20 3a 20 5b 20 7b 0a 20 20 20 20 22 74 69 74 6c 65 22 20 3a 20 22 54 65 72 6d 73 20 6f 66 20 53 65 72 76 69 63 65 22 2c 0a 20 20 20 20 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 3a 20 5b 20 22 42 79 20 75 73 69 6e 67 20 74 68 65 20 41 52 49 4e 20 52 44 41 50 2f 57 68 6f 69 73 20 73 65 72 76 69 63 65 2c 20 79 6f 75 20 61 72 65 20 61 67 72 65 65 69 6e 67 20 74 6f 20 74 68 65 20 52 44 41 50 2f 57 68 6f 69 73 20 54 65 72 6d 73 20 6f 66 20 55 73 65 22 20
                                            Data Ascii: { "rdapConformance" : [ "nro_rdap_profile_0", "rdap_level_0", "cidr0", "arin_originas0" ], "notices" : [ { "title" : "Terms of Service", "description" : [ "By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use"
                                            2024-02-05 22:00:55 UTC1274INData Raw: 31 39 33 2e 38 38 2e 30 22 2c 0a 20 20 20 20 20 20 22 72 65 6c 22 20 3a 20 22 73 65 6c 66 22 2c 0a 20 20 20 20 20 20 22 74 79 70 65 22 20 3a 20 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 72 64 61 70 2b 6a 73 6f 6e 22 2c 0a 20 20 20 20 20 20 22 68 72 65 66 22 20 3a 20 22 68 74 74 70 73 3a 2f 2f 72 64 61 70 2e 61 72 69 6e 2e 6e 65 74 2f 72 65 67 69 73 74 72 79 2f 65 6e 74 69 74 79 2f 42 55 4c 2d 35 22 0a 20 20 20 20 7d 2c 20 7b 0a 20 20 20 20 20 20 22 76 61 6c 75 65 22 20 3a 20 22 68 74 74 70 73 3a 2f 2f 72 64 61 70 2e 61 72 69 6e 2e 6e 65 74 2f 72 65 67 69 73 74 72 79 2f 69 70 2f 31 30 34 2e 31 39 33 2e 38 38 2e 30 22 2c 0a 20 20 20 20 20 20 22 72 65 6c 22 20 3a 20 22 61 6c 74 65 72 6e 61 74 65 22 2c 0a 20 20 20 20 20 20 22 74 79 70 65 22 20 3a 20 22 61 70 70
                                            Data Ascii: 193.88.0", "rel" : "self", "type" : "application/rdap+json", "href" : "https://rdap.arin.net/registry/entity/BUL-5" }, { "value" : "https://rdap.arin.net/registry/ip/104.193.88.0", "rel" : "alternate", "type" : "app
                                            2024-02-05 22:00:55 UTC2548INData Raw: 70 6f 6e 73 65 20 66 72 6f 6d 20 74 68 65 20 50 4f 43 20 73 69 6e 63 65 20 32 30 31 38 2d 31 31 2d 32 33 22 20 5d 0a 20 20 20 20 20 20 7d 20 5d 2c 0a 20 20 20 20 20 20 22 6c 69 6e 6b 73 22 20 3a 20 5b 20 7b 0a 20 20 20 20 20 20 20 20 22 76 61 6c 75 65 22 20 3a 20 22 68 74 74 70 73 3a 2f 2f 72 64 61 70 2e 61 72 69 6e 2e 6e 65 74 2f 72 65 67 69 73 74 72 79 2f 69 70 2f 31 30 34 2e 31 39 33 2e 38 38 2e 30 22 2c 0a 20 20 20 20 20 20 20 20 22 72 65 6c 22 20 3a 20 22 73 65 6c 66 22 2c 0a 20 20 20 20 20 20 20 20 22 74 79 70 65 22 20 3a 20 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 72 64 61 70 2b 6a 73 6f 6e 22 2c 0a 20 20 20 20 20 20 20 20 22 68 72 65 66 22 20 3a 20 22 68 74 74 70 73 3a 2f 2f 72 64 61 70 2e 61 72 69 6e 2e 6e 65 74 2f 72 65 67 69 73 74 72 79 2f 65 6e
                                            Data Ascii: ponse from the POC since 2018-11-23" ] } ], "links" : [ { "value" : "https://rdap.arin.net/registry/ip/104.193.88.0", "rel" : "self", "type" : "application/rdap+json", "href" : "https://rdap.arin.net/registry/en
                                            2024-02-05 22:00:55 UTC154INData Raw: 74 43 6c 61 73 73 4e 61 6d 65 22 20 3a 20 22 69 70 20 6e 65 74 77 6f 72 6b 22 2c 0a 20 20 22 63 69 64 72 30 5f 63 69 64 72 73 22 20 3a 20 5b 20 7b 0a 20 20 20 20 22 76 34 70 72 65 66 69 78 22 20 3a 20 22 31 30 34 2e 31 39 33 2e 38 38 2e 30 22 2c 0a 20 20 20 20 22 6c 65 6e 67 74 68 22 20 3a 20 32 32 0a 20 20 7d 20 5d 2c 0a 20 20 22 61 72 69 6e 5f 6f 72 69 67 69 6e 61 73 30 5f 6f 72 69 67 69 6e 61 75 74 6e 75 6d 73 22 20 3a 20 5b 20 35 35 39 36 37 20 5d 0a 7d
                                            Data Ascii: tClassName" : "ip network", "cidr0_cidrs" : [ { "v4prefix" : "104.193.88.0", "length" : 22 } ], "arin_originas0_originautnums" : [ 55967 ]}


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            3192.168.2.549711199.71.0.1604433472C:\Program Files\Google\Chrome\Application\chrome.exe
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:55 UTC606OUTGET /favicon.ico HTTP/1.1
                                            Host: rdap.arin.net
                                            Connection: keep-alive
                                            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                            sec-ch-ua-mobile: ?0
                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                            sec-ch-ua-platform: "Windows"
                                            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                            Sec-Fetch-Site: same-origin
                                            Sec-Fetch-Mode: no-cors
                                            Sec-Fetch-Dest: image
                                            Referer: https://rdap.arin.net/registry/ip/104.193.88.0
                                            Accept-Encoding: gzip, deflate, br
                                            Accept-Language: en-US,en;q=0.9
                                            2024-02-05 22:00:55 UTC199INHTTP/1.1 404 Not Found
                                            Date: Mon, 05 Feb 2024 22:00:55 GMT
                                            Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips
                                            Content-Length: 209
                                            Connection: close
                                            Content-Type: text/html; charset=iso-8859-1
                                            2024-02-05 22:00:55 UTC209INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                            Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /favicon.ico was not found on this server.</p></body></html>


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            4192.168.2.54971523.63.206.91443
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:58 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                            Connection: Keep-Alive
                                            Accept: */*
                                            Accept-Encoding: identity
                                            User-Agent: Microsoft BITS/7.8
                                            Host: fs.microsoft.com
                                            2024-02-05 22:00:58 UTC532INHTTP/1.1 200 OK
                                            Content-Type: application/octet-stream
                                            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                            X-Ms-ApiVersion: Distribute 1.2
                                            X-Ms-Region: prod-eus2-z1
                                            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                            X-MSEdge-Ref: Ref A: 90C84EA9CA4A4456B4B8E5C805E289EC Ref B: BLUEDGE1612 Ref C: 2024-02-03T17:34:19Z
                                            Cache-Control: public, max-age=70381
                                            Date: Mon, 05 Feb 2024 22:00:58 GMT
                                            Connection: close
                                            X-CID: 2


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            5192.168.2.54971623.63.206.91443
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:00:58 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                            Connection: Keep-Alive
                                            Accept: */*
                                            Accept-Encoding: identity
                                            If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                            Range: bytes=0-2147483646
                                            User-Agent: Microsoft BITS/7.8
                                            Host: fs.microsoft.com
                                            2024-02-05 22:00:59 UTC661INHTTP/1.1 200 OK
                                            Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                            ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                            Content-Type: application/octet-stream
                                            ApiVersion: Distribute 1.1
                                            Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                            X-CID: 7
                                            X-CCC: US
                                            X-Azure-Ref-OriginShield: Ref A: 77D3A374A575439792C03F9D3B3E5A6A Ref B: CH1AA2040903034 Ref C: 2023-07-19T16:59:25Z
                                            X-MSEdge-Ref: Ref A: 268FB40D90624D4B909B4269BE9DB868 Ref B: CHI30EDGE0106 Ref C: 2023-07-19T17:02:00Z
                                            Cache-Control: public, max-age=70438
                                            Date: Mon, 05 Feb 2024 22:00:58 GMT
                                            Content-Length: 55
                                            Connection: close
                                            X-CID: 2
                                            2024-02-05 22:00:59 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                            Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                            Session IDSource IPSource PortDestination IPDestination Port
                                            6192.168.2.54972223.1.237.91443
                                            TimestampBytes transferredDirectionData
                                            2024-02-05 22:01:06 UTC2148OUTPOST /threshold/xls.aspx HTTP/1.1
                                            Origin: https://www.bing.com
                                            Referer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init
                                            Accept: */*
                                            Accept-Language: en-CH
                                            Content-type: text/xml
                                            X-Agent-DeviceId: 01000A410900D492
                                            X-BM-CBT: 1696428841
                                            X-BM-DateFormat: dd/MM/yyyy
                                            X-BM-DeviceDimensions: 784x984
                                            X-BM-DeviceDimensionsLogical: 784x984
                                            X-BM-DeviceScale: 100
                                            X-BM-DTZ: 120
                                            X-BM-Market: CH
                                            X-BM-Theme: 000000;0078d7
                                            X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E
                                            X-Device-ClientSession: DB0AFB19004F47BC80E5208C7478FF22
                                            X-Device-isOptin: false
                                            X-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}
                                            X-Device-OSSKU: 48
                                            X-Device-Touch: false
                                            X-DeviceID: 01000A410900D492
                                            X-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,staticsh
                                            X-MSEdge-ExternalExpType: JointCoord
                                            X-PositionerType: Desktop
                                            X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI
                                            X-Search-CortanaAvailableCapabilities: None
                                            X-Search-SafeSearch: Moderate
                                            X-Search-TimeZone: Bias=-60; DaylightBias=-60; TimeZoneKeyName=W. Europe Standard Time
                                            X-UserAgeClass: Unknown
                                            Accept-Encoding: gzip, deflate, br
                                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045
                                            Host: www.bing.com
                                            Content-Length: 2484
                                            Connection: Keep-Alive
                                            Cache-Control: no-cache
                                            Cookie: MUID=2F4E96DB8B7049E59AD4484C3C00F7CF; _SS=SID=1A6DEABB468B65843EB5F91B47916435&CPID=1707170434021&AC=1&CPH=d1a4eb75; _EDGE_S=SID=1A6DEABB468B65843EB5F91B47916435; SRCHUID=V=2&GUID=3D32B8AC657C4AD781A584E283227995&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231004; SRCHHPGUSR=SRCHLANG=en&IPMH=986d886c&IPMID=1696428841029&HV=1696428756; CortanaAppUID=5A290E2CC4B523E2D8B5E2E3E4CB7CB7; MUIDB=2F4E96DB8B7049E59AD4484C3C00F7CF
                                            2024-02-05 22:01:06 UTC1OUTData Raw: 3c
                                            Data Ascii: <
                                            2024-02-05 22:01:06 UTC2483OUTData Raw: 43 6c 69 65 6e 74 49 6e 73 74 52 65 71 75 65 73 74 3e 3c 43 49 44 3e 33 36 34 34 46 44 37 34 44 46 31 36 36 31 38 46 30 38 46 37 45 43 30 33 44 45 35 35 36 30 30 31 3c 2f 43 49 44 3e 3c 45 76 65 6e 74 73 3e 3c 45 3e 3c 54 3e 45 76 65 6e 74 2e 43 6c 69 65 6e 74 49 6e 73 74 3c 2f 54 3e 3c 49 47 3e 37 35 32 32 38 31 35 36 37 30 33 41 34 30 44 35 42 39 37 45 35 41 36 38 33 36 46 32 41 31 43 45 3c 2f 49 47 3e 3c 44 3e 3c 21 5b 43 44 41 54 41 5b 7b 22 43 75 72 55 72 6c 22 3a 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 2f 41 53 2f 41 50 49 2f 57 69 6e 64 6f 77 73 43 6f 72 74 61 6e 61 50 61 6e 65 2f 56 32 2f 49 6e 69 74 22 2c 22 50 69 76 6f 74 22 3a 22 51 46 22 2c 22 54 22 3a 22 43 49 2e 42 6f 78 4d 6f 64 65 6c 22 2c 22 46 49 44 22 3a 22 43 49
                                            Data Ascii: ClientInstRequest><CID>3644FD74DF16618F08F7EC03DE556001</CID><Events><E><T>Event.ClientInst</T><IG>75228156703A40D5B97E5A6836F2A1CE</IG><D><![CDATA[{"CurUrl":"https://www.bing.com/AS/API/WindowsCortanaPane/V2/Init","Pivot":"QF","T":"CI.BoxModel","FID":"CI
                                            2024-02-05 22:01:06 UTC475INHTTP/1.1 204 No Content
                                            Access-Control-Allow-Origin: *
                                            Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                            X-MSEdge-Ref: Ref A: 1CDF98BC61E445C5B3A91AE7260AE8E7 Ref B: BY3EDGE0416 Ref C: 2024-02-05T22:01:06Z
                                            Date: Mon, 05 Feb 2024 22:01:06 GMT
                                            Connection: close
                                            Alt-Svc: h3=":443"; ma=93600
                                            X-CDN-TraceID: 0.57ed0117.1707170466.1eecf37


                                            020406080s020406080100

                                            Click to jump to process

                                            020406080s0.0050100MB

                                            Click to jump to process

                                            Target ID:0
                                            Start time:23:00:46
                                            Start date:05/02/2024
                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                            Imagebase:0x7ff715980000
                                            File size:3'242'272 bytes
                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low
                                            Has exited:false

                                            Target ID:2
                                            Start time:23:00:50
                                            Start date:05/02/2024
                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2224,i,8779192040810359767,11844691577958903530,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                            Imagebase:0x7ff715980000
                                            File size:3'242'272 bytes
                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low
                                            Has exited:false

                                            Target ID:3
                                            Start time:23:00:53
                                            Start date:05/02/2024
                                            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rdap.arin.net/registry/ip/104.193.88.0
                                            Imagebase:0x7ff715980000
                                            File size:3'242'272 bytes
                                            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low
                                            Has exited:true
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                            No disassembly