Edit tour

Windows Analysis Report
https://a11ybar.com/ok6.js

Overview

General Information

Sample URL:https://a11ybar.com/ok6.js
Analysis ID:1400288
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1448 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 1072 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2200,i,2431694887396778904,17462009629836117578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 6600 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://a11ybar.com/ok6.js MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://a11ybar.com/ok6.jsHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.221.242.90
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /ok6.js HTTP/1.1Host: a11ybar.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: a11ybar.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://a11ybar.com/ok6.jsAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: a11ybar.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: a11ybar.com
Source: chromecache_41.2.dr, chromecache_42.2.drString found in binary or memory: https://try.monday.com/j135mq1rvvbl
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.221.242.90:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/5@7/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2200,i,2431694887396778904,17462009629836117578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://a11ybar.com/ok6.js
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2200,i,2431694887396778904,17462009629836117578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1400288 URL: https://a11ybar.com/ok6.js Startdate: 28/02/2024 Architecture: WINDOWS Score: 0 14 time.windows.com 2->14 16 fp2e7a.wpc.phicdn.net 2->16 18 fp2e7a.wpc.2be4.phicdn.net 2->18 6 chrome.exe 1 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 20 192.168.2.102 unknown unknown 6->20 22 192.168.2.7, 138, 443, 49699 unknown unknown 6->22 24 239.255.255.250 unknown Reserved 6->24 11 chrome.exe 6->11         started        process5 dnsIp6 26 www.google.com 172.253.62.106, 443, 49711, 49722 GOOGLEUS United States 11->26 28 a11ybar.com 104.21.56.218, 443, 49706, 49707 CLOUDFLARENETUS United States 11->28 30 172.67.136.238, 443, 49709 CLOUDFLARENETUS United States 11->30

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://a11ybar.com/ok6.js0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://a11ybar.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.253.62.106
truefalse
    high
    a11ybar.com
    104.21.56.218
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        time.windows.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://a11ybar.com/ok6.jsfalse
            unknown
            https://a11ybar.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://try.monday.com/j135mq1rvvblchromecache_41.2.dr, chromecache_42.2.drfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              172.67.136.238
              unknownUnited States
              13335CLOUDFLARENETUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              172.253.62.106
              www.google.comUnited States
              15169GOOGLEUSfalse
              104.21.56.218
              a11ybar.comUnited States
              13335CLOUDFLARENETUSfalse
              IP
              192.168.2.102
              192.168.2.7
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1400288
              Start date and time:2024-02-28 16:02:10 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 15s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://a11ybar.com/ok6.js
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:17
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/5@7/6
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.251.167.94, 172.253.63.102, 172.253.63.139, 172.253.63.113, 172.253.63.100, 172.253.63.138, 172.253.63.101, 172.253.63.84, 34.104.35.123, 168.61.215.74, 20.114.59.183, 23.207.202.25, 192.229.211.108, 104.96.220.107, 104.96.220.104, 20.166.126.56, 72.21.81.240, 13.95.31.18, 23.207.202.42, 23.207.202.6, 23.207.202.13, 23.207.202.12, 23.207.202.7, 23.207.202.9, 23.207.202.10, 23.207.202.5, 23.207.202.41, 23.207.202.38, 23.207.202.37, 23.207.202.40, 172.253.62.94, 23.207.202.15, 23.207.202.22, 23.207.202.21, 23.207.202.20, 23.207.202.14, 23.207.202.16
              • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, twc.trafficmanager.net, clientservices.googleapis.com, a767.dspw65.akamai.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://a11ybar.com/ok6.js
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:ASCII text, with CRLF line terminators
              Category:downloaded
              Size (bytes):141
              Entropy (8bit):4.784373198763856
              Encrypted:false
              SSDEEP:3:q0oBiRyRmgO9lNHWAUafRAU6/GY+ovEEkjX2DGZ9LRzlLBFTvn:qM8mgO9lVhnZXm+ov6jX2DGZ9L1lLBJv
              MD5:83CB13AF83103C0462F2887B9E2E59FC
              SHA1:BBA2C6F03A513588A6001980E7E11CFDA068D2A2
              SHA-256:AE723359F13E5593E4C492C99A8D4751A3349EFC137FB3EA701A991C4867B242
              SHA-512:DCC8381FACF78E829897B4CF3868D284139AFD54C834B86CC3A1EA11E9E9110D4552B4AA26F135EDD72B4E40DDE853531861050F017605EA0D977FA075EC950E
              Malicious:false
              Reputation:low
              URL:https://a11ybar.com/ok6.js
              Preview:var js = document.createElement("script");..js.type = "text/javascript";..js.src = "//a11ybar.com/stat.js";..document.body.appendChild(js);..
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:dropped
              Size (bytes):165
              Entropy (8bit):5.043197498357468
              Encrypted:false
              SSDEEP:3:IuFADyM6IdFKsWTDfiSA+qQOuaM/FUtWf4GpvIbzWEo4G6v2lqXtPL:IUA2oNZSA+noFIs6bvI9
              MD5:1F784A903271104AB6B9B0FBFF7762B5
              SHA1:773E1082DCEAAECDA85E2618DBAE749A69312C03
              SHA-256:781669358DE6B6B1E627C1FFBB3584268A3FA7359AEF1FDC2C7B6D7D562C63F5
              SHA-512:717C7BA90FF0B9E276D04A0D44183711BE763CC161E16F312528BB3D9441A4E031E7D327EA506FDC33E2795579FE447D038343D49CF4D2D1BA6988C3F15CECCB
              Malicious:false
              Reputation:low
              Preview:.<center><a href="https://try.monday.com/j135mq1rvvbl" target="_blank" rel="noopener"><img src="/1080x1080 Facebook - DV360_projects done right.png" border="0"></a>.
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):165
              Entropy (8bit):5.043197498357468
              Encrypted:false
              SSDEEP:3:IuFADyM6IdFKsWTDfiSA+qQOuaM/FUtWf4GpvIbzWEo4G6v2lqXtPL:IUA2oNZSA+noFIs6bvI9
              MD5:1F784A903271104AB6B9B0FBFF7762B5
              SHA1:773E1082DCEAAECDA85E2618DBAE749A69312C03
              SHA-256:781669358DE6B6B1E627C1FFBB3584268A3FA7359AEF1FDC2C7B6D7D562C63F5
              SHA-512:717C7BA90FF0B9E276D04A0D44183711BE763CC161E16F312528BB3D9441A4E031E7D327EA506FDC33E2795579FE447D038343D49CF4D2D1BA6988C3F15CECCB
              Malicious:false
              Reputation:low
              URL:https://a11ybar.com/favicon.ico
              Preview:.<center><a href="https://try.monday.com/j135mq1rvvbl" target="_blank" rel="noopener"><img src="/1080x1080 Facebook - DV360_projects done right.png" border="0"></a>.
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 97
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Feb 28, 2024 16:02:57.758265018 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:02:58.070430994 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:02:58.679810047 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:02:59.039180994 CET49674443192.168.2.7104.98.116.138
              Feb 28, 2024 16:02:59.041929007 CET49675443192.168.2.7104.98.116.138
              Feb 28, 2024 16:02:59.132924080 CET49672443192.168.2.7104.98.116.138
              Feb 28, 2024 16:02:59.882972002 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:03:02.304821014 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:03:04.563122034 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.563162088 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.563235998 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.563982010 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.564016104 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.564071894 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.564219952 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.564234018 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.564572096 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.564585924 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.841583967 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.841970921 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.841995955 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.843183994 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.843290091 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.844317913 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.844410896 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.844549894 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.844558001 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.845558882 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.847403049 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.847419024 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.848910093 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.849071980 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.849421978 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.849498987 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.922497034 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.922497034 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:04.922512054 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:04.968002081 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.257307053 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.257433891 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.257587910 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.259150982 CET49706443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.259167910 CET44349706104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.304760933 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.345932007 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.530801058 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.531033993 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.531092882 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.534015894 CET49707443192.168.2.7104.21.56.218
              Feb 28, 2024 16:03:05.534038067 CET44349707104.21.56.218192.168.2.7
              Feb 28, 2024 16:03:05.685022116 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.685051918 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.685112000 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.685499907 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.685513973 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.938925028 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.939268112 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.939280987 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.940329075 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.940413952 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.940880060 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.940942049 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.941029072 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:05.941050053 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:05.992568970 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:06.305727005 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:06.429327965 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:06.429424047 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:06.429478884 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:06.466682911 CET49709443192.168.2.7172.67.136.238
              Feb 28, 2024 16:03:06.466707945 CET44349709172.67.136.238192.168.2.7
              Feb 28, 2024 16:03:06.681798935 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:06.848093033 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:06.848128080 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:06.848191977 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:06.849404097 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:06.849419117 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.043622017 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.087749958 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.119008064 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:03:07.158684015 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.158700943 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.159967899 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.160048008 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.162942886 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.163017988 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.212748051 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.212766886 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:07.255986929 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:07.429708958 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:08.648456097 CET49674443192.168.2.7104.98.116.138
              Feb 28, 2024 16:03:08.648472071 CET49675443192.168.2.7104.98.116.138
              Feb 28, 2024 16:03:08.742217064 CET49672443192.168.2.7104.98.116.138
              Feb 28, 2024 16:03:08.929734945 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:09.043054104 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.043081999 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.043203115 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.045691967 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.045706987 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.247222900 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.247293949 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.254935980 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.254942894 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.255224943 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.320616007 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.797557116 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.841901064 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.890607119 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.891135931 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.891171932 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.891184092 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.891376972 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.891415119 CET4434971223.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.891474009 CET49712443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.937848091 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.937882900 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:09.938249111 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.938249111 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:09.938286066 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.122514009 CET44349699104.98.116.138192.168.2.7
              Feb 28, 2024 16:03:10.122664928 CET49699443192.168.2.7104.98.116.138
              Feb 28, 2024 16:03:10.136506081 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.136668921 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.139185905 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.139193058 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.139535904 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.140952110 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.181907892 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.318022966 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.341701984 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.341811895 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.341912031 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.341912031 CET49713443192.168.2.723.221.242.90
              Feb 28, 2024 16:03:10.341932058 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:10.341941118 CET4434971323.221.242.90192.168.2.7
              Feb 28, 2024 16:03:11.914397001 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:16.727421999 CET49671443192.168.2.7204.79.197.203
              Feb 28, 2024 16:03:17.061928034 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:17.062011957 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:17.062079906 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:17.698482037 CET49711443192.168.2.7172.253.62.106
              Feb 28, 2024 16:03:17.698514938 CET44349711172.253.62.106192.168.2.7
              Feb 28, 2024 16:03:17.868052006 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:03:29.774413109 CET49677443192.168.2.720.50.201.200
              Feb 28, 2024 16:04:06.772077084 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:06.772119999 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:06.772192955 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:06.773422956 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:06.773448944 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:06.964473009 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:06.965960026 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:06.965993881 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:06.966371059 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:06.970107079 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:06.970244884 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:07.024260044 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:16.961129904 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:16.961296082 CET44349722172.253.62.106192.168.2.7
              Feb 28, 2024 16:04:16.961378098 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:17.912266016 CET49722443192.168.2.7172.253.62.106
              Feb 28, 2024 16:04:17.912297010 CET44349722172.253.62.106192.168.2.7
              TimestampSource PortDest PortSource IPDest IP
              Feb 28, 2024 16:03:03.578444004 CET53623261.1.1.1192.168.2.7
              Feb 28, 2024 16:03:03.589318991 CET53548331.1.1.1192.168.2.7
              Feb 28, 2024 16:03:04.183542013 CET53619801.1.1.1192.168.2.7
              Feb 28, 2024 16:03:04.436116934 CET5617853192.168.2.71.1.1.1
              Feb 28, 2024 16:03:04.436327934 CET5990053192.168.2.71.1.1.1
              Feb 28, 2024 16:03:04.560394049 CET53599001.1.1.1192.168.2.7
              Feb 28, 2024 16:03:04.562324047 CET53561781.1.1.1192.168.2.7
              Feb 28, 2024 16:03:05.557485104 CET5794253192.168.2.71.1.1.1
              Feb 28, 2024 16:03:05.557796001 CET6302053192.168.2.71.1.1.1
              Feb 28, 2024 16:03:05.682384014 CET53579421.1.1.1192.168.2.7
              Feb 28, 2024 16:03:05.684429884 CET53630201.1.1.1192.168.2.7
              Feb 28, 2024 16:03:06.720782995 CET5620153192.168.2.71.1.1.1
              Feb 28, 2024 16:03:06.721401930 CET6208353192.168.2.71.1.1.1
              Feb 28, 2024 16:03:06.845514059 CET53620831.1.1.1192.168.2.7
              Feb 28, 2024 16:03:06.845935106 CET53562011.1.1.1192.168.2.7
              Feb 28, 2024 16:03:11.064604998 CET5196053192.168.2.71.1.1.1
              Feb 28, 2024 16:03:21.260376930 CET53553041.1.1.1192.168.2.7
              Feb 28, 2024 16:03:40.243258953 CET53533051.1.1.1192.168.2.7
              Feb 28, 2024 16:04:03.022202969 CET53511801.1.1.1192.168.2.7
              Feb 28, 2024 16:04:03.300601959 CET53601611.1.1.1192.168.2.7
              Feb 28, 2024 16:04:06.834117889 CET138138192.168.2.7192.168.2.255
              Feb 28, 2024 16:04:31.445214033 CET53503071.1.1.1192.168.2.7
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Feb 28, 2024 16:03:04.436116934 CET192.168.2.71.1.1.10x9845Standard query (0)a11ybar.comA (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:04.436327934 CET192.168.2.71.1.1.10x137dStandard query (0)a11ybar.com65IN (0x0001)false
              Feb 28, 2024 16:03:05.557485104 CET192.168.2.71.1.1.10xdfa7Standard query (0)a11ybar.comA (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:05.557796001 CET192.168.2.71.1.1.10x457aStandard query (0)a11ybar.com65IN (0x0001)false
              Feb 28, 2024 16:03:06.720782995 CET192.168.2.71.1.1.10xa894Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.721401930 CET192.168.2.71.1.1.10xe3aStandard query (0)www.google.com65IN (0x0001)false
              Feb 28, 2024 16:03:11.064604998 CET192.168.2.71.1.1.10x1b9aStandard query (0)time.windows.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Feb 28, 2024 16:03:04.560394049 CET1.1.1.1192.168.2.70x137dNo error (0)a11ybar.com65IN (0x0001)false
              Feb 28, 2024 16:03:04.562324047 CET1.1.1.1192.168.2.70x9845No error (0)a11ybar.com104.21.56.218A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:04.562324047 CET1.1.1.1192.168.2.70x9845No error (0)a11ybar.com172.67.136.238A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:05.682384014 CET1.1.1.1192.168.2.70xdfa7No error (0)a11ybar.com172.67.136.238A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:05.682384014 CET1.1.1.1192.168.2.70xdfa7No error (0)a11ybar.com104.21.56.218A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:05.684429884 CET1.1.1.1192.168.2.70x457aNo error (0)a11ybar.com65IN (0x0001)false
              Feb 28, 2024 16:03:06.845514059 CET1.1.1.1192.168.2.70xe3aNo error (0)www.google.com65IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.106A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.105A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.104A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.147A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.99A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:06.845935106 CET1.1.1.1192.168.2.70xa894No error (0)www.google.com172.253.62.103A (IP address)IN (0x0001)false
              Feb 28, 2024 16:03:11.187345028 CET1.1.1.1192.168.2.70x1b9aNo error (0)time.windows.comtwc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
              Feb 28, 2024 16:03:19.932934046 CET1.1.1.1192.168.2.70x9e5bNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Feb 28, 2024 16:03:19.932934046 CET1.1.1.1192.168.2.70x9e5bNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
              • a11ybar.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.749706104.21.56.2184431072C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-02-28 15:03:04 UTC660OUTGET /ok6.js HTTP/1.1
              Host: a11ybar.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-02-28 15:03:05 UTC678INHTTP/1.1 200 OK
              Date: Wed, 28 Feb 2024 15:03:05 GMT
              Content-Type: text/javascript; charset=UTF-8
              Transfer-Encoding: chunked
              Connection: close
              X-Powered-By: PHP/5.4.16
              Access-Control-Allow-Origin: *
              ETag: 3f989fbea15d3f3ac06d3c4e3f47d068
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=VbJhhwPzn15R%2BKHGPknpKW2hdothey15RW0F95bvHLfysq554nYQ6IhO1kPHkN5VvrJ0Xha%2FxpQ0nvUC2pnh5Rw0GgCtTAOkxRJihm1PSNDG%2Fj%2F4UwIXqraj5OeEqg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 85c98d607eb6580c-IAD
              alt-svc: h3=":443"; ma=86400
              2024-02-28 15:03:05 UTC147INData Raw: 38 64 0d 0a 76 61 72 20 6a 73 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 22 73 63 72 69 70 74 22 29 3b 0d 0a 6a 73 2e 74 79 70 65 20 3d 20 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3b 0d 0a 6a 73 2e 73 72 63 20 3d 20 22 2f 2f 61 31 31 79 62 61 72 2e 63 6f 6d 2f 73 74 61 74 2e 6a 73 22 3b 0d 0a 64 6f 63 75 6d 65 6e 74 2e 62 6f 64 79 2e 61 70 70 65 6e 64 43 68 69 6c 64 28 6a 73 29 3b 0d 0a 0d 0a
              Data Ascii: 8dvar js = document.createElement("script");js.type = "text/javascript";js.src = "//a11ybar.com/stat.js";document.body.appendChild(js);
              2024-02-28 15:03:05 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.749707104.21.56.2184431072C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-02-28 15:03:05 UTC584OUTGET /favicon.ico HTTP/1.1
              Host: a11ybar.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://a11ybar.com/ok6.js
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-02-28 15:03:05 UTC625INHTTP/1.1 200 OK
              Date: Wed, 28 Feb 2024 15:03:05 GMT
              Content-Type: text/html
              Transfer-Encoding: chunked
              Connection: close
              Last-Modified: Mon, 30 Oct 2023 16:11:16 GMT
              Accept-Ranges: bytes
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=BY1sUb4Jyu0prcTG%2BOOajFDs7ZyMEQ1KTaFXzc2EUs1gwFiqG3eFpm10%2B43WtrYStzAY5n1K95Gd0ANeRWKA8mURnqZhQk%2BeAvPXm4xjPbi0Zi73uVuR0nBBbEEueQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 85c98d626f1b87ac-IAD
              alt-svc: h3=":443"; ma=86400
              2024-02-28 15:03:05 UTC171INData Raw: 61 35 0d 0a 0a 3c 63 65 6e 74 65 72 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 74 72 79 2e 6d 6f 6e 64 61 79 2e 63 6f 6d 2f 6a 31 33 35 6d 71 31 72 76 76 62 6c 22 20 74 61 72 67 65 74 3d 22 5f 62 6c 61 6e 6b 22 20 72 65 6c 3d 22 6e 6f 6f 70 65 6e 65 72 22 3e 3c 69 6d 67 20 73 72 63 3d 22 2f 31 30 38 30 78 31 30 38 30 20 46 61 63 65 62 6f 6f 6b 20 2d 20 44 56 33 36 30 5f 70 72 6f 6a 65 63 74 73 20 64 6f 6e 65 20 72 69 67 68 74 2e 70 6e 67 22 20 62 6f 72 64 65 72 3d 22 30 22 3e 3c 2f 61 3e 0a 0d 0a
              Data Ascii: a5<center><a href="https://try.monday.com/j135mq1rvvbl" target="_blank" rel="noopener"><img src="/1080x1080 Facebook - DV360_projects done right.png" border="0"></a>
              2024-02-28 15:03:05 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.749709172.67.136.2384431072C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-02-28 15:03:05 UTC346OUTGET /favicon.ico HTTP/1.1
              Host: a11ybar.com
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: */*
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: cors
              Sec-Fetch-Dest: empty
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-02-28 15:03:06 UTC627INHTTP/1.1 200 OK
              Date: Wed, 28 Feb 2024 15:03:06 GMT
              Content-Type: text/html
              Transfer-Encoding: chunked
              Connection: close
              Last-Modified: Mon, 30 Oct 2023 16:11:16 GMT
              Accept-Ranges: bytes
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=h6GF8dY8bOmHvE6BTQF2t07encLhGp%2FpODMDMnQKWACSoRLBgWI9sL2ntMDAGFPv5qM307K%2BnzcmjTliLOb7vG%2FwJTGg1PqGAYu5wbd3gPGbkgtgx%2BU2mrJFesXSXw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 85c98d676eea8797-IAD
              alt-svc: h3=":443"; ma=86400
              2024-02-28 15:03:06 UTC171INData Raw: 61 35 0d 0a 0a 3c 63 65 6e 74 65 72 3e 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 74 72 79 2e 6d 6f 6e 64 61 79 2e 63 6f 6d 2f 6a 31 33 35 6d 71 31 72 76 76 62 6c 22 20 74 61 72 67 65 74 3d 22 5f 62 6c 61 6e 6b 22 20 72 65 6c 3d 22 6e 6f 6f 70 65 6e 65 72 22 3e 3c 69 6d 67 20 73 72 63 3d 22 2f 31 30 38 30 78 31 30 38 30 20 46 61 63 65 62 6f 6f 6b 20 2d 20 44 56 33 36 30 5f 70 72 6f 6a 65 63 74 73 20 64 6f 6e 65 20 72 69 67 68 74 2e 70 6e 67 22 20 62 6f 72 64 65 72 3d 22 30 22 3e 3c 2f 61 3e 0a 0d 0a
              Data Ascii: a5<center><a href="https://try.monday.com/j135mq1rvvbl" target="_blank" rel="noopener"><img src="/1080x1080 Facebook - DV360_projects done right.png" border="0"></a>
              2024-02-28 15:03:06 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.74971223.221.242.90443
              TimestampBytes transferredDirectionData
              2024-02-28 15:03:09 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-02-28 15:03:09 UTC494INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (chd/073D)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=15801
              Date: Wed, 28 Feb 2024 15:03:09 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.74971323.221.242.90443
              TimestampBytes transferredDirectionData
              2024-02-28 15:03:10 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-02-28 15:03:10 UTC773INHTTP/1.1 200 OK
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              X-CID: 7
              X-CCC: US
              X-Azure-Ref-OriginShield: Ref A: 8BFC17DD061B46CAAD2B2AEB7B19C3D8 Ref B: CH1AA2040901011 Ref C: 2023-07-21T06:04:00Z
              X-MSEdge-Ref: Ref A: 1421F39FA7224BE199CC2F2C3DD24574 Ref B: CHI30EDGE0415 Ref C: 2023-07-21T06:04:00Z
              Content-Type: application/octet-stream
              X-Azure-Ref: 0DMGnYgAAAACXaXykPZuVRq4aV6pCkeO8U0pDRURHRTAzMTgAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
              Cache-Control: public, max-age=15777
              Date: Wed, 28 Feb 2024 15:03:10 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-02-28 15:03:10 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              Target ID:0
              Start time:16:02:58
              Start date:28/02/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff6c4390000
              File size:3'242'272 bytes
              MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:16:03:01
              Start date:28/02/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2200,i,2431694887396778904,17462009629836117578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff6c4390000
              File size:3'242'272 bytes
              MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:16:03:03
              Start date:28/02/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://a11ybar.com/ok6.js
              Imagebase:0x7ff6c4390000
              File size:3'242'272 bytes
              MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              No disassembly